Vulnerability index

Browse CVEs

21 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Zenphoto HIGH 7.2
CVE-2020-36079

Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the upload…

Fix: after 1.5.7
Fix from $1,950 2021-02-26
Zenphoto HIGH 8.8
CVE-2020-5593

Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.

Fix: 1.5.7+
Fix from $1,950 2020-06-11
Zenphoto MEDIUM 6.1
CVE-2020-5592

Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vect…

Fix: 1.5.7+
Fix from $1,600 2020-06-11
Zenphoto MEDIUM 6.1
CVE-2012-4519

Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.

Fix: 1.4.3.4+
Fix from $1,600 2020-02-11
Zenphoto MEDIUM 6.5
CVE-2015-5595

Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin u…

Fix: 1.4.9+
Fix from $1,600 2019-12-31
Zenphoto MEDIUM 6.1
CVE-2015-5593

The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scr…

Fix: 1.4.9+
Fix from $1,600 2019-12-31
Zenphoto HIGH 7.2
CVE-2015-5591

SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.

Fix: 1.4.9+
Fix from $1,950 2019-12-31
Zenphoto MEDIUM 6.1
CVE-2015-5592

Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.

Fix: 1.4.9+
Fix from $1,600 2019-12-31
Zenphoto MEDIUM 6.1
CVE-2018-20140

Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.

Patch available
Fix from $1,600 2019-03-21
Zenphoto HIGH 7.2
CVE-2018-0610

Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code…

Fix: after 1.4.14
Fix from $1,950 2018-06-26
Zenphoto MEDIUM 6.1
CVE-2015-5594

The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attac…

Fix: after 1.4.8
Fix from $1,600 2017-07-25
Zenphoto MEDIUM 6.5
CVE-2013-7242

SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to ex…

Fix: after 1.4.5.3
Fix from $1,600 2013-12-31
Zenphoto MEDIUM 6.8
CVE-2012-0993

Eval injection vulnerability in zp-core/zp-extensions/viewer_size_image.php in ZENphoto 1.4.2, when the viewer_size_image plugin is enabled, allows r…

Patch available
Fix from $1,600 2012-02-21
Zenphoto MEDIUM 6.0
CVE-2012-0994

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execut…

Patch available
Fix from $1,600 2012-02-21
Zenphoto HIGH 7.5
CVE-2010-4906

SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a…

Mitigation only
Fix from $1,950 2011-10-08
Zenphoto HIGH 7.5
CVE-2009-4566

SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a new…

Mitigation only
Fix from $1,950 2010-01-04
Zenphoto MEDIUM 6.8
CVE-2009-4564

SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL comm…

No fix yet
Fix from $1,600 2010-01-04
Zenphoto HIGH 7.5
CVE-2007-6666

SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parame…

No fix yet
Fix from $1,950 2008-01-04
Zenphoto HIGH 7.8
CVE-2007-0616

Directory traversal vulnerability in zen/template-functions.php in zenphoto 1.0.4 up to 1.0.6 allows remote attackers to list arbitrary directories v…

No fix yet
Fix from $1,950 2007-01-31
Zenphoto MEDIUM 6.8
CVE-2006-2187

Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML …

Fix: after 1.0.1_beta
Fix from $1,600 2006-05-04
Zenphoto MEDIUM 5.0
CVE-2006-2186

zenphoto 1.0.1 beta and earlier allow remote attackers to obtain sensitive information via a direct request for the (1) /photos/themes/default/ and (…

Patch available
Fix from $1,600 2006-05-04