Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Menalto

First CVE: Jan 17, 2008Active for: 19 yearsTotal CVEs: 23
31.3
VTI Score
Medium

Menalto developed a suite of web-based digital asset and gallery management applications, including the core Gallery platform and specialized modules such as Gallery Publish XP and Gallery Webcam, which occupy a niche but notably durable position within the media-management software landscape. The vulnerability footprint centers on application-layer weaknesses characteristic of web software: cross-site scripting flaws, path-traversal and input-validation issues, and information-disclosure vulnerabilities that arise from web page generation and file-access logic. While the product portfolio is narrow, Menalto's presence in the top tier of prominence reflects the widespread and long-running deployment of these applications across photo-sharing and media sites. Defenders maintaining legacy Gallery installations should prioritize input-handling advisories and access-control disclosures; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
1.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Menalto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 17, 2008
18 years ago
Most Recent CVE
Oct 10, 2013
4,670 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2012-2405HIGH
Gallery 2 before 2.3.2 and 3 before 3.0.3 does not properly implement encryption, which has unspecified impact and attack vectors, a different vulnerability than CVE-2012-1113.
Apr 22, 201210.029NONO
CVE-2007-6685HIGH
Unspecified vulnerability in the Publish XP module Menalto Gallery before 2.2.4 allows attackers to create albums and upload files via unknown vectors.
Jan 17, 200810.025NONO
CVE-2007-6686HIGH
The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.
Jan 17, 200810.025NONO
CVE-2007-6688HIGH
Unspecified vulnerability in the Installation application in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to "web-accessibility protection of the stor
Jan 17, 200810.025NONO
CVE-2007-6690HIGH
The Gallery Remote module in Menalto Gallery before 2.2.4 does not check permissions for unspecified GR commands, which has unknown impact and attack vectors.
Jan 17, 200810.025NONO
CVE-2007-6691HIGH
Multiple unspecified vulnerabilities in Menalto Gallery before 2.2.4 have unknown impact, related to (1) "hotlink protection" in the URL rewrite module, (2) a WebDAV view in the We
Jan 17, 200810.025NONO
CVE-2007-6693HIGH
Unspecified vulnerability in the WebCam module in Menalto Gallery before 2.2.4 has unknown impact and attack vectors related to a "proxied request."
Jan 17, 200810.025NONO
CVE-2013-2240HIGH
lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a differ
Oct 10, 20137.523NONO
CVE-2012-4343HIGH
Multiple unspecified vulnerabilities in Gallery 3 before 3.0.4 allow attackers to execute arbitrary PHP code via unknown vectors.
Aug 15, 20127.522NONO
CVE-2007-6689HIGH
Menalto Gallery before 2.2.4 does not properly check for malicious file extensions during file uploads, which allows attackers to execute arbitrary code via the (1) Core applicatio
Jan 17, 20087.521NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
48%
52%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown23 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown23 (100.0%)
User Interaction
None0 (0.0%)
Unknown23 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown23 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Menalto.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Menalto — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Menalto's Products

View all 2 CNAs →

Top CWEs