


Perceptive Security
SOC/SIEM Consultancy

Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting…
Published:
31 May 2026 at 22:00:00
Alert date:
1 June 2026 at 23:04:16
Source:
nvd.nist.gov
Web Technologies
CVE-2018-25433 affects Joomla Component JE Photo Gallery version 1.1, containing an SQL injection vulnerability in the categoryid parameter. Unauthenticated attackers can exploit this vulnerability by sending crafted GET requests to index.php with malicious categoryid values in the com_jephotogallery component. The vulnerability allows execution of arbitrary SQL queries against the database. Attackers can extract sensitive information including usernames and password hashes. This represents a significant security risk for websites using the affected component version.
Technical details
Mitigation steps:
Affected products:
Joomla JE Photo Gallery
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25433
http://joomlaextensions.co.in/download/1387375463_JE%20PhotoGallery%20(%20J-%203.0%20).zip
https://joomlaextensions.co.in
https://www.exploit-db.com/exploits/45930
https://www.vulncheck.com/advisories/joomla-je-photo-gallery-sql-injection-via-categoryid
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
