CVE-2026-38467: SQL Injection
Published Aug 25, 2026
·Updated
A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 allows remote authenticated users with usersmod privileges to execute arbitrary SQL commands via the tagid or type parameter in a crafted POST request to tools.php?action=managetags.
Affected Software
1 affected component
GazellePW GazellePosterWall
Event History
Aug 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·10:17 PM
Description