Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zenphoto vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2018-0610
Local file inclusion vulnerability in Zenphoto 1.4.14 and previous versions allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.
Zenphoto Zenphoto
4.3
CVSSv2
CVE-2015-5594
The sanitize_string function in ZenPhoto prior to 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote malicious users to perform a cross-site scripting (XSS) via a crafted string.
Zenphoto Zenphoto
1 EDB exploit
4.3
CVSSv2
CVE-2015-2949
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Zenphoto Zenphoto
4.3
CVSSv2
CVE-2015-2948
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto prior to 1.4.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Zenphoto Zenphoto
6.5
CVSSv2
CVE-2013-7242
SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto prior to 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.
Zenphoto Zenphoto
Zenphoto Zenphoto 1.4.5.1
Zenphoto Zenphoto 1.4.5.2
Zenphoto Zenphoto 1.4.5
4.3
CVSSv2
CVE-2013-7241
Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto prior to 1.4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the URI.
Zenphoto Zenphoto
Zenphoto Zenphoto 1.4.5.1
Zenphoto Zenphoto 1.4.5.2
Zenphoto Zenphoto 1.4.5
4.3
CVSSv2
CVE-2012-2641
Cross-site scripting (XSS) vulnerability in Zenphoto prior to 1.4.3 allows remote malicious users to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.
Zenphoto Zenphoto 1.0.6
Zenphoto Zenphoto 1.0.4
Zenphoto Zenphoto 1.3.1.2
Zenphoto Zenphoto
Zenphoto Zenphoto 1.0
Zenphoto Zenphoto 1.0.1
Zenphoto Zenphoto 1.1.3
Zenphoto Zenphoto 1.1.1
Zenphoto Zenphoto 1.1.7
Zenphoto Zenphoto 1.1.2
Zenphoto Zenphoto 1.2.5
Zenphoto Zenphoto 0.9
Zenphoto Zenphoto 1.0.5
Zenphoto Zenphoto 1.1
Zenphoto Zenphoto 1.3
6.8
CVSSv2
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote malicious users to execute arbitrary PHP code via the viewer_size_image_saved cookie.
Zenphoto Zenphoto 1.4.2
6
CVSSv2
CVE-2012-0994
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.
Zenphoto Zenphoto 1.4.2
4.3
CVSSv2
CVE-2012-0995
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH...
Zenphoto Zenphoto 1.4.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »