Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Coppermine Gallery

First CVE: Dec 3, 2005Active for: 21 yearsTotal CVEs: 40

Coppermine Gallery is a self-hosted web-based photo gallery and management application that has accumulated a modest vulnerability footprint relative to its presence in the self-hosted and community-deployed software ecosystem. The exposure centers on its core photo gallery product and reflects the typical input-handling and access-control concerns that arise in PHP-based web applications. Defenders should treat this vendor's advisories as relevant primarily to self-hosted deployments rather than as broadly applicable to large enterprise or cloud infrastructure; current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Coppermine Gallery over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 3, 2005
20 years ago
Most Recent CVE
Dec 15, 2025
222 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-1614MEDIUM
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page
Sep 4, 20125.031NOYES
CVE-2010-4815CRITICAL
Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution.
Feb 5, 20209.830NONO
CVE-2008-3486HIGH
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, all
Aug 6, 20087.530NOYES
CVE-2023-53868HIGH
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can
Dec 15, 20258.828NONO
CVE-2008-3481HIGH
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the install
Aug 5, 20087.528NOYES
CVE-2008-0504MEDIUM
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) album
Jan 31, 20086.526NOYES
CVE-2012-1613LOW
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary
Sep 4, 20123.523NOYES
CVE-2010-4693MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (
Jan 11, 20114.323NOYES
CVE-2018-14478MEDIUM
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
May 7, 20196.122NONO
CVE-2011-2476MEDIUM
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a d
Jun 14, 20114.318NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
10%
70%
15%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (20.0%)
Unknown16 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (20.0%)
High0 (0.0%)
Unknown16 (80.0%)
User Interaction
None2 (10.0%)
Unknown16 (80.0%)
Required2 (10.0%)
Privileges Required
Low1 (5.0%)
High0 (0.0%)
None3 (15.0%)
Unknown16 (80.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Coppermine Gallery.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Coppermine Gallery — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Coppermine Gallery's Products

View all 3 CNAs →

Top CWEs