EIP-2026-108577

PRE-CVE

Joomla! Component com_videogallery - Local File Inclusion / SQL Injection

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108577. PoCs published by KedAns-Dz.

AI-analyzed exploit summary The provided text describes local file inclusion (LFI) and SQL injection (SQLi) vulnerabilities in the Video Gallery component for Joomla!. It includes example URLs demonstrating how an attacker could exploit these vulnerabilities by manipulating input parameters.

Description

Joomla! Component com_videogallery - Local File Inclusion / SQL Injection

Exploits (1)

exploitdb WRITEUP VERIFIED
by KedAns-Dz · textwebappsphp
https://www.exploit-db.com/exploits/37102

The provided text describes local file inclusion (LFI) and SQL injection (SQLi) vulnerabilities in the Video Gallery component for Joomla!. It includes example URLs demonstrating how an attacker could exploit these vulnerabilities by manipulating input parameters.

Classification
Writeup 90%
Attack Type
Sqli | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Joomla! Video Gallery component
No auth needed
Prerequisites: Access to the vulnerable Joomla! instance
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026