4homepages maintains a web-based gallery and content-management product line centered on 4images, which attracts a web-application vulnerability profile dominated by input-handling and code-generation flaws. The recurring weakness classes—cross-site scripting, code injection, path traversal, and improper input validation—are characteristic of gallery and templating software where user-supplied content and server-side code generation intersect. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 4homepages over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1022HIGH SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action. | Feb 8, 2012 | 7.5 | 30 | NO | YES |
CVE-2021-27308MEDIUM A cross-site scripting (XSS) vulnerability in the admin login panel in 4images version 1.8 allows remote attackers to inject JavaScript via the "redirect" parameter. | Mar 22, 2021 | 4.8 | 28 | NO | YES |
CVE-2006-5236HIGH SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter. | Oct 11, 2006 | 7.5 | 28 | NO | YES |
CVE-2012-1023MEDIUM Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redi | Feb 8, 2012 | 5.8 | 27 | NO | YES |
CVE-2009-2132MEDIUM Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via | Jun 19, 2009 | 6.8 | 27 | NO | YES |
CVE-2012-1021MEDIUM Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter in | Feb 8, 2012 | 4.3 | 24 | NO | YES |
CVE-2022-50806HIGH 4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attacker | Jan 13, 2026 | 7.2 | 22 | NO | NO |
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitrary web script or HTML by providing a crafted user_homepage | Jun 19, 2009 | 3.5 | 19 | NO | YES |
CVE-2020-35853MEDIUM 4images Image Gallery Management System 1.7.11 is affected by cross-site scripting (XSS) in the Image URL. This vulnerability can result in an attacker to inject the XSS payload in | Jan 26, 2021 | 4.8 | 17 | NO | NO |
Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involvin | Apr 25, 2006 | 2.6 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 4homepages.
Media articles that mention a CVE ID that affects a product developed by 4homepages — matched by CVE ID, not by vendor name.