Coppermine Gallery is a self-hosted web-based photo gallery and management application that has accumulated a modest vulnerability footprint relative to its presence in the self-hosted and community-deployed software ecosystem. The exposure centers on its core photo gallery product and reflects the typical input-handling and access-control concerns that arise in PHP-based web applications. Defenders should treat this vendor's advisories as relevant primarily to self-hosted deployments rather than as broadly applicable to large enterprise or cloud infrastructure; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coppermine Gallery over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1614MEDIUM Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page | Sep 4, 2012 | 5.0 | 31 | NO | YES |
CVE-2010-4815CRITICAL Coppermine gallery before 1.4.26 has an input validation vulnerability that allows for code execution. | Feb 5, 2020 | 9.8 | 30 | NO | NO |
CVE-2008-3486HIGH Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, all | Aug 6, 2008 | 7.5 | 30 | NO | YES |
CVE-2023-53868HIGH Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can | Dec 15, 2025 | 8.8 | 28 | NO | NO |
CVE-2008-3481HIGH themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the install | Aug 5, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-0504MEDIUM Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) album | Jan 31, 2008 | 6.5 | 26 | NO | YES |
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary | Sep 4, 2012 | 3.5 | 23 | NO | YES |
CVE-2010-4693MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and ( | Jan 11, 2011 | 4.3 | 23 | NO | YES |
CVE-2018-14478MEDIUM ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter. | May 7, 2019 | 6.1 | 22 | NO | NO |
CVE-2011-2476MEDIUM Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a d | Jun 14, 2011 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coppermine Gallery.
Media articles that mention a CVE ID that affects a product developed by Coppermine Gallery — matched by CVE ID, not by vendor name.