๐Ÿ” CVE Alert

CVE-2026-25868

UNKNOWN 0.0

MiniGal Nano <= 0.3.5 Reflected XSS via dir Parameter

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/JavaScript that is reflected in the response. Successful exploitation can lead to execution of arbitrary script in a victim's browser in the context of the vulnerable application.

CWE CWE-79
Vendor minigal
Product minigal nano
Published Feb 11, 2026
Last Updated Mar 5, 2026
Stay Ahead of the Next One

Get instant alerts for minigal minigal nano

Be the first to know when new unknown vulnerabilities affecting minigal minigal nano are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MiniGal / MiniGal Nano
0 โ‰ค 0.3.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
web.archive.org: https://web.archive.org/web/20180330004313/http://www.minigal.dk/minigal-nano.html sourceforge.net: https://sourceforge.net/projects/minigalnano/ vulncheck.com: https://www.vulncheck.com/advisories/minigal-nano-reflected-xss-via-dir-parameter

Credits

philopentest