Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gnu
Gnu nano |
|
| CPEs | cpe:2.3:a:gnu:nano:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu nano |
Thu, 26 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rybber
Rybber minigal Nano |
|
| CPEs | cpe:2.3:a:rybber:minigal_nano:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rybber
Rybber minigal Nano |
|
| Metrics |
cvssV3_1
|
Wed, 11 Feb 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Minigal
Minigal minigal |
|
| Vendors & Products |
Minigal
Minigal minigal |
|
| Metrics |
ssvc
|
Wed, 11 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 11 Feb 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MiniGal Nano version 0.3.5 and prior contain a reflected cross-site scripting (XSS) vulnerability in index.php via the dir parameter. The application constructs $currentdir from user-controlled input and embeds it into an error message without output encoding, allowing an attacker to supply HTML/JavaScript that is reflected in the response. Successful exploitation can lead to execution of arbitrary script in a victim's browser in the context of the vulnerable application. | |
| Title | MiniGal Nano <= 0.3.5 Reflected XSS via dir Parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-05T01:30:55.511Z
Reserved: 2026-02-06T19:12:03.464Z
Link: CVE-2026-25868
Updated: 2026-02-11T21:40:42.856Z
Status : Analyzed
Published: 2026-02-11T16:16:06.657
Modified: 2026-02-26T20:30:30.263
Link: CVE-2026-25868
No data.
OpenCVE Enrichment
Updated: 2026-04-16T17:15:17Z