Minigal is a lightweight image gallery application, with vulnerabilities observed across its core Minigal and MG2 product lines, centered on web-layer input handling and path management flaws including cross-site scripting, path traversal, and related input-validation issues. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minigal over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2145HIGH The imagecomments function in classes.php in MiniGal b13 allows remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the input parameter. NOTE: s | Apr 19, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-2146HIGH The imagecomments function in classes.php in MiniGal b13 allow remote attackers to inject arbitrary PHP code into a file in the thumbs/ directory via the (1) name or (2) email para | Apr 19, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-6933MEDIUM Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code of .php files, and possibly the content of other files, via | Aug 11, 2009 | 5.0 | 23 | NO | YES |
CVE-2008-1228MEDIUM Cross-site scripting (XSS) vulnerability in admin.php in MG2 (formerly Minigal) allows remote attackers to inject arbitrary web script or HTML via the list parameter in an import a | Mar 10, 2008 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minigal.
Media articles that mention a CVE ID that affects a product developed by Minigal — matched by CVE ID, not by vendor name.