Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2020-36079
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the upload…
Zenphoto
after 1.5.7
HIGH 8.8
CVE-2020-5593
Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.
Zenphoto
1.5.7+
MEDIUM 6.1
CVE-2020-5592
Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vect…
Zenphoto
1.5.7+
MEDIUM 6.1
CVE-2012-4519
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.
Zenphoto
1.4.3.4+
MEDIUM 6.5
CVE-2015-5595
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin u…
Zenphoto
1.4.9+
MEDIUM 6.1
CVE-2015-5593
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scr…
Zenphoto
1.4.9+
HIGH 7.2
CVE-2015-5591
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
Zenphoto
1.4.9+
MEDIUM 6.1
CVE-2015-5592
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
Zenphoto
1.4.9+
MEDIUM 6.1
CVE-2018-20140
Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
Zenphoto
Patch available
HIGH 7.2
CVE-2018-0610
Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code…
Zenphoto
after 1.4.14
MEDIUM 6.1
CVE-2015-5594
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attac…
Zenphoto
after 1.4.8
MEDIUM 6.5
CVE-2013-7242
SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to ex…
Zenphoto
after 1.4.5.3
MEDIUM 6.8
CVE-2012-0993
Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows r…
Zenphoto
Patch available
MEDIUM 6.0
CVE-2012-0994
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execut…
Zenphoto
Patch available
HIGH 7.5
CVE-2010-4906
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a…
Zenphoto
Mitigation only
HIGH 7.5
CVE-2009-4566
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a new…
Zenphoto
Mitigation only
MEDIUM 6.8
CVE-2009-4564
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL comm…
Zenphoto
No fix yet
HIGH 7.5
CVE-2007-6666
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parame…
Zenphoto
No fix yet
HIGH 7.8
CVE-2007-0616
Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories v…
Zenphoto
No fix yet
MEDIUM 6.8
CVE-2006-2187
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML …
Zenphoto
after 1.0.1_beta
MEDIUM 5.0
CVE-2006-2186
zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (…
Zenphoto
Patch available