Xooscripts' vulnerability footprint centers on XooGallery, a gallery and media-management component, where the durable signal reflects application-layer input-handling weaknesses, particularly SQL injection in database query construction. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xooscripts over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25522CRITICAL XooGallery Latest contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to manipulate database queries by injecting SQL code through the photo_id par | Mar 12, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25521CRITICAL XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the gal_id parameter. A | Mar 12, 2026 | 9.1 | 29 | NO | NO |
CVE-2019-25524CRITICAL XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'p' parameter. Atta | Mar 12, 2026 | 9.1 | 28 | NO | NO |
CVE-2019-25523CRITICAL XooGallery Latest contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the cat_id parameter. A | Mar 12, 2026 | 9.1 | 28 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xooscripts.
Media articles that mention a CVE ID that affects a product developed by Xooscripts — matched by CVE ID, not by vendor name.