Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zenphoto zenphoto vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2015-2949
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Zenphoto Zenphoto
383
VMScore
CVE-2012-0995
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH...
Zenphoto Zenphoto 1.4.2
435
VMScore
CVE-2010-4907
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.3 allows remote malicious users to inject arbitrary web script or HTML via the user parameter. NOTE: the from parameter is already covered by CVE-2009-4562.
Zenphoto Zenphoto 1.3
1 EDB exploit
383
VMScore
CVE-2018-20140
Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
Zenphoto Zenphoto 1.4.14
383
VMScore
CVE-2008-6925
Cross-site scripting (XSS) vulnerability in function.php in Zenphoto 1.1.7 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors in the "request logging" feature. NOTE: the provenance of this information is unknown; the details are...
Zenphoto Zenphoto 1.1.7
605
VMScore
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote malicious users to execute arbitrary PHP code via the viewer_size_image_saved cookie.
Zenphoto Zenphoto 1.4.2
534
VMScore
CVE-2012-0994
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.
Zenphoto Zenphoto 1.4.2
435
VMScore
CVE-2009-4562
Cross-site scripting (XSS) vulnerability in zp-core/admin.php in Zenphoto 1.2.5 allows remote malicious users to inject arbitrary web script or HTML via the from parameter.
Zenphoto Zenphoto 1.2.5
1 EDB exploit
435
VMScore
CVE-2009-4563
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote malicious users to hijack the authentication of administrators for requests that change the administrative password via the 0-adminpass and 0-adminpass_2 parameters in a s...
Zenphoto Zenphoto 1.2.5
1 EDB exploit
685
VMScore
CVE-2009-4564
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote malicious users to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.
Zenphoto Zenphoto 1.2.5
1 EDB exploit
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
privilege escalation
CVE-2024-20696
CVE-2024-29829
CVE-2024-33999
CVE-2024-35646
physical
CVE-2024-24919
CVE-2024-31030
local users
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »