Linpha is a modestly represented photo gallery application whose vulnerability profile centers on web-application input-handling and disclosure weaknesses recurrent across its single product. The vendor's disclosures tend to acquire public exploit code and cluster around cross-site scripting, path traversal, improper input validation, and sensitive information exposure—typical attack surfaces for user-facing gallery and content-management functionality. Defenders should apply patches promptly given the public availability of working exploits; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Linpha over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4053HIGH SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the order parameter to new_image | Jul 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-1856MEDIUM plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modifies the configuration file, which allows remote attackers to | Apr 16, 2008 | 5.1 | 25 | NO | YES |
CVE-2004-2066HIGH SQL injection vulnerability in session.php in LinPHA 0.9.4 allows remote attackers to execute arbitrary SQL code and bypass authentication via the (1) linpha_userid or (2) linpha_p | Jul 29, 2004 | 7.5 | 24 | NO | NO |
CVE-2006-0713MEDIUM Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequences in the (1) lang parameter in docs/index.php and the la | Feb 15, 2006 | 5.0 | 23 | NO | YES |
CVE-2011-3753MEDIUM LinPHA 1.3.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated b | Sep 23, 2011 | 5.0 | 17 | NO | NO |
CVE-2006-1924MEDIUM SQL injection vulnerability in functions/db_api.php in LinPHA 1.1.1 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | Apr 20, 2006 | 6.4 | 17 | NO | NO |
CVE-2006-1923MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) RSS/RSS.php and (2) possibly other | Apr 20, 2006 | 5.8 | 16 | NO | NO |
CVE-2014-7265MEDIUM Cross-site scripting (XSS) vulnerability in LinPHA allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Dec 12, 2014 | 4.3 | 14 | NO | NO |
CVE-2008-7223MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.3 allow remote attackers to inject arbitrary web script or HTML via (1) ftp/index.php, (2) viewer.php, (3) | Sep 14, 2009 | 4.3 | 14 | NO | NO |
CVE-2008-6571MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in LinPHA before 1.3.4 might allow remote attackers to inject arbitrary web script or HTML via (1) new_images.php, (2) login.php | Mar 31, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Linpha.
Media articles that mention a CVE ID that affects a product developed by Linpha — matched by CVE ID, not by vendor name.