Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
zenphoto vulnerabilities and exploits
(subscribe to this query)
7.2
CVSSv3
CVE-2018-0610
Local file inclusion vulnerability in Zenphoto 1.4.14 and previous versions allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.
Zenphoto Zenphoto
6.1
CVSSv3
CVE-2015-5594
The sanitize_string function in ZenPhoto prior to 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote malicious users to perform a cross-site scripting (XSS) via a crafted string.
Zenphoto Zenphoto
1 EDB exploit
NA
CVE-2015-2948
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto prior to 1.4.8 allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Zenphoto Zenphoto
NA
CVE-2015-2949
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and previous versions allows remote malicious users to inject arbitrary web script or HTML via unspecified vectors.
Zenphoto Zenphoto
NA
CVE-2013-7241
Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto prior to 1.4.5.4 allows remote malicious users to inject arbitrary web script or HTML via the URI.
Zenphoto Zenphoto
Zenphoto Zenphoto 1.4.5.1
Zenphoto Zenphoto 1.4.5.2
Zenphoto Zenphoto 1.4.5
NA
CVE-2013-7242
SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto prior to 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.
Zenphoto Zenphoto
Zenphoto Zenphoto 1.4.5.1
Zenphoto Zenphoto 1.4.5.2
Zenphoto Zenphoto 1.4.5
NA
CVE-2012-2641
Cross-site scripting (XSS) vulnerability in Zenphoto prior to 1.4.3 allows remote malicious users to inject arbitrary web script or HTML by triggering improper interaction with an unspecified library.
Zenphoto Zenphoto 1.0.6
Zenphoto Zenphoto 1.0.4
Zenphoto Zenphoto 1.3.1.2
Zenphoto Zenphoto
Zenphoto Zenphoto 1.0
Zenphoto Zenphoto 1.0.1
Zenphoto Zenphoto 1.1.3
Zenphoto Zenphoto 1.1.1
Zenphoto Zenphoto 1.1.7
Zenphoto Zenphoto 1.1.2
Zenphoto Zenphoto 1.2.5
Zenphoto Zenphoto 0.9
Zenphoto Zenphoto 1.0.5
Zenphoto Zenphoto 1.1
Zenphoto Zenphoto 1.3
NA
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows remote malicious users to execute arbitrary PHP code via the viewer_size_image_saved cookie.
Zenphoto Zenphoto 1.4.2
NA
CVE-2012-0994
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.
Zenphoto Zenphoto 1.4.2
NA
CVE-2012-0995
Multiple cross-site scripting (XSS) vulnerabilities in ZENphoto 1.4.2 allow remote malicious users to inject arbitrary web script or HTML via the (1) msg parameter in an external action to zp-core/admin.php, (2) PATH_INTO to an unspecified URL, as demonstrated using /1/, (3) PATH...
Zenphoto Zenphoto 1.4.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
spoof
CVE-2024-34928
CVE-2024-5291
deserialization
CVE-2024-4471
CVE-2024-4956
CVE-2024-32002
CVE-2024-5227
unspecified
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »