CVE-2026-25868
MiniGal Nano <= 0.3.5 Reflected XSS via dir Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/JavaScript that is reflected in the response. Successful exploitation can lead to execution of arbitrary script in a victim's browser in the context of the vulnerable application.
| CWE | CWE-79 |
| Vendor | minigal |
| Product | minigal nano |
| Published | Feb 11, 2026 |
| Last Updated | Mar 5, 2026 |
Stay Ahead of the Next One
Get instant alerts for minigal minigal nano
Be the first to know when new unknown vulnerabilities affecting minigal minigal nano are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MiniGal / MiniGal Nano
0 โค 0.3.5
References
Credits
philopentest