Vulnerabilities > Zenphoto
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-12-21 | CVE-2022-44449 | Cross-site Scripting vulnerability in Zenphoto Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script. | 4.8 |
2021-02-26 | CVE-2020-36079 | Unrestricted Upload of File with Dangerous Type vulnerability in Zenphoto Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. | 7.2 |
2020-06-11 | CVE-2020-5593 | Code Injection vulnerability in Zenphoto Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file. | 8.8 |
2020-06-11 | CVE-2020-5592 | Cross-site Scripting vulnerability in Zenphoto Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vectors. | 6.1 |
2020-02-11 | CVE-2012-4519 | Cross-site Scripting vulnerability in Zenphoto Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS. | 6.1 |
2019-12-31 | CVE-2015-5595 | Cross-Site Request Forgery (CSRF) vulnerability in Zenphoto Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption). | 6.5 |
2019-12-31 | CVE-2015-5593 | Cross-site Scripting vulnerability in Zenphoto The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>payload<script></script></script>", or in an image tag, with the payload as the onerror event. | 6.1 |
2019-12-31 | CVE-2015-5592 | Cross-site Scripting vulnerability in Zenphoto Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks. | 6.1 |
2019-12-31 | CVE-2015-5591 | SQL Injection vulnerability in Zenphoto SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. | 7.2 |
2019-03-21 | CVE-2018-20140 | Cross-site Scripting vulnerability in Zenphoto 1.4.14 Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters. | 6.1 |