Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zenphoto zenphoto vulnerabilities and exploits
(subscribe to this query)
578
VMScore
CVE-2020-5593
Zenphoto versions before 1.5.7 allows an malicious user to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.
Zenphoto Zenphoto
383
VMScore
CVE-2008-6925
Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are...
Zenphoto Zenphoto 1.1.7
383
VMScore
CVE-2012-0995
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH...
Zenphoto Zenphoto 1.4.2
605
VMScore
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote malicious users to execute arbitrary PHP code via the viewer_size_image_saved cookie.
Zenphoto Zenphoto 1.4.2
435
VMScore
CVE-2010-4907
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote malicious users to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
Zenphoto Zenphoto 1.3
1 EDB exploit
534
VMScore
CVE-2012-0994
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.
Zenphoto Zenphoto 1.4.2
383
VMScore
CVE-2018-20140
Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
Zenphoto Zenphoto 1.4.14
435
VMScore
CVE-2009-4563
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote malicious users to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a s...
Zenphoto Zenphoto 1.2.5
1 EDB exploit
685
VMScore
CVE-2009-4564
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote malicious users to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.
Zenphoto Zenphoto 1.2.5
1 EDB exploit
435
VMScore
CVE-2009-4562
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote malicious users to inject arbitrary web script or HTML via the from parameter.
Zenphoto Zenphoto 1.2.5
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
logic flaw
CVE-2024-23692
CVE-2024-26229
CVE-2024-35255
CVE-2024-5835
CVE-2024-5837
XML external entity
dos
CVE-2024-5813
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »