zenphoto
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting zenphoto.
- CVE-2023-53916Zenphoto 1.6 Stored Cross-Site Scripting via User Postal Code Field4.6
- CVE-2023-53915Zenphoto 1.6 Stored Cross-Site Scripting via Album Description4.6
- CVE-2022-44449Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.4.8
- CVE-2020-36079Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag...7.2
- CVE-2020-5593Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.8.8
- CVE-2020-5592Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vectors.6.1
- CVE-2012-4519Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.6.1
- CVE-2015-5595Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of ser...6.5
- CVE-2015-5593The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<...6.1
- CVE-2015-5592Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.6.1
- CVE-2015-5591SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.7.2
- CVE-2018-20140Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.6.1
- CVE-2018-0610Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.7.2
- CVE-2015-5594The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via...6.1
- CVE-2015-2949Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3