Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2020-36079 Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the upload… Zenphoto after 1.5.7 Fix from $1,9502021-02-26 HIGH 8.8 CVE-2020-5593 Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file. Zenphoto 1.5.7+ Fix from $1,9502020-06-11 MEDIUM 6.1 CVE-2020-5592 Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vect… Zenphoto 1.5.7+ Fix from $1,6002020-06-11 MEDIUM 6.1 CVE-2012-4519 Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS. Zenphoto 1.4.3.4+ Fix from $1,6002020-02-11 MEDIUM 6.5 CVE-2015-5595 Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin u… Zenphoto 1.4.9+ Fix from $1,6002019-12-31 MEDIUM 6.1 CVE-2015-5593 The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scr… Zenphoto 1.4.9+ Fix from $1,6002019-12-31 HIGH 7.2 CVE-2015-5591 SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. Zenphoto 1.4.9+ Fix from $1,9502019-12-31 MEDIUM 6.1 CVE-2015-5592 Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks. Zenphoto 1.4.9+ Fix from $1,6002019-12-31 MEDIUM 6.1 CVE-2018-20140 Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. Zenphoto Patch available Fix from $1,6002019-03-21 HIGH 7.2 CVE-2018-0610 Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code… Zenphoto after 1.4.14 Fix from $1,9502018-06-26 MEDIUM 6.1 CVE-2015-5594 The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attac… Zenphoto after 1.4.8 Fix from $1,6002017-07-25 MEDIUM 6.5 CVE-2013-7242 SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to ex… Zenphoto after 1.4.5.3 Fix from $1,6002013-12-31 MEDIUM 6.8 CVE-2012-0993 Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows r… Zenphoto Patch available Fix from $1,6002012-02-21 MEDIUM 6.0 CVE-2012-0994 SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execut… Zenphoto Patch available Fix from $1,6002012-02-21 HIGH 7.5 CVE-2010-4906 SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a… Zenphoto Mitigation only Fix from $1,9502011-10-08 HIGH 7.5 CVE-2009-4566 SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a new… Zenphoto Mitigation only Fix from $1,9502010-01-04 MEDIUM 6.8 CVE-2009-4564 SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL comm… Zenphoto No fix yet Fix from $1,6002010-01-04 HIGH 7.5 CVE-2007-6666 SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parame… Zenphoto No fix yet Fix from $1,9502008-01-04 HIGH 7.8 CVE-2007-0616 Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories v… Zenphoto No fix yet Fix from $1,9502007-01-31 MEDIUM 6.8 CVE-2006-2187 Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML … Zenphoto after 1.0.1_beta Fix from $1,6002006-05-04 MEDIUM 5.0 CVE-2006-2186 zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (… Zenphoto Patch available Fix from $1,6002006-05-04