Easyimages2.0 is a web-based image-management application with a concentrated vulnerability footprint that skews toward serious outcomes across a modestly represented but notably positioned codebase. The recurring exposure pattern centers on web-application input handling and file-management operations, manifesting through cross-site scripting, unrestricted file uploads, cross-site request forgery, path-traversal conditions, and code-injection weaknesses that are characteristic of server-side image-processing platforms. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easyimages2.0 Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65474CRITICAL An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to | Dec 11, 2025 | 9.8 | 33 | NO | NO |
CVE-2025-65473CRITICAL An arbitrary file rename vulnerability in the /admin/filer.php component of EasyImages 2.0 v2.8.6 and below allows attackers with Administrator privileges to execute arbitrary code | Dec 11, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-65471HIGH An arbitrary file upload vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via uploading a crafted PHP | Dec 11, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-65472HIGH A Cross-Site Request Forgery (CSRF) in the /admin/admin.inc.php component of EasyImages 2.0 v2.8.6 and below allows attackers to escalate privileges to Administrator via user inter | Dec 11, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-33599MEDIUM EasyImages2.0 ≤ 2.8.1 is vulnerable to Cross Site Scripting (XSS) via viewlog.php. | May 23, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-1181MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository icret/easyimages2.0 prior to 2.6.7. | Mar 5, 2023 | 5.4 | 20 | NO | NO |
CVE-2025-13415MEDIUM A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php of the component SVG Image Handler. The manipulation of the | Nov 19, 2025 | 5.4 | 19 | NO | NO |
CVE-2023-7098MEDIUM ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in icret EasyImages 2.8.3. This vulnerability affects unknown code of the file app/hide.php. The | Dec 25, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easyimages2.0 Project.
Media articles that mention a CVE ID that affects a product developed by Easyimages2.0 Project — matched by CVE ID, not by vendor name.