Coppermine Photo Gallery is a web-based image management and sharing application that, despite a narrow product scope, occupies a notable position in the vulnerability landscape owing to its long history and persistent deployment across content management and media-sharing sites. The vendor's disclosures concentrate on application-layer input-handling and validation weaknesses, including cross-site scripting, SQL injection, path traversal, and improper input validation, which are characteristic of server-side web applications that process user-supplied content and file paths. Public exploit code has frequently been made available for vulnerabilities in this product, reflecting both the accessibility of web-application attack surfaces and the product's visibility among researchers and attackers. Defenders should prioritize patches for this vendor's releases, especially those affecting authentication and file-access boundaries, and inventory instances exposed to untrusted networks; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coppermine over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0506MEDIUM include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute ar | Jan 31, 2008 | 6.8 | 67 | NO | YES |
CVE-2004-1988HIGH PHP remote file inclusion vulnerability in init.inc.php in Coppermine Photo Gallery 1.2.0 RC4 allows remote attackers to execute arbitrary PHP code by modifying the CPG_M_DIR to re | Apr 30, 2004 | 7.5 | 39 | NO | YES |
CVE-2007-0122MEDIUM Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat pa | Jan 9, 2007 | 6.5 | 32 | NO | YES |
CVE-2004-1989HIGH PHP remote file inclusion vulnerability in theme.php in Coppermine Photo Gallery 1.2.2b allows remote attackers to execute arbitrary PHP code by modifying the THEME_DIR parameter t | Apr 30, 2004 | 7.5 | 32 | NO | YES |
CVE-2007-4976MEDIUM Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary lo | Sep 19, 2007 | 6.5 | 31 | NO | YES |
CVE-2007-4283HIGH PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the sour | Aug 9, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-4321HIGH PHP remote file inclusion vulnerability in cpg.php in the Coppermine Photo Gallery component (com_cpg) 1.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP co | Aug 24, 2006 | 7.5 | 29 | NO | YES |
CVE-2026-3013HIGH Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct p | Mar 11, 2026 | 8.7 | 28 | NO | NO |
CVE-2007-3558HIGH SQL injection vulnerability in Coppermine Photo Gallery (CPG) before 1.4.11 allows remote attackers to execute arbitrary SQL commands via an album password cookie to an unspecified | Jul 4, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-1107HIGH SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users to execute arbitrary SQL commands via a cpg131_fav cookie. | Feb 26, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coppermine.
Media articles that mention a CVE ID that affects a product developed by Coppermine — matched by CVE ID, not by vendor name.