Photopost maintains a focused line of PHP-based gallery and community-content platforms, including Photopost PHP Pro and ReviewPost PHP Pro, that have achieved notable deployment across web communities and niche hosting environments. While the vendor's disclosures are modest in volume, they recur around input-validation and code-injection weaknesses characteristic of server-side PHP applications handling user-supplied content and templates. The vendor's vulnerability profile is distinguished by a strong tendency toward public exploit availability, reflecting the appeal of these platforms to both attackers developing proof-of-concept tooling and operators of legacy web properties seeking to understand exposure. Defenders managing instances of these products should prioritize patching cycles and restrict administrative interfaces, as older versions remain in service across distributed hosting and remain targets for reconnaissance and lateral movement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Photopost over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0251HIGH Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors. | Jan 12, 2008 | 10.0 | 36 | NO | YES |
CVE-2004-0239HIGH SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable. | Nov 23, 2004 | 10.0 | 35 | NO | YES |
CVE-2005-0271HIGH Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) pr | Jan 3, 2005 | 7.5 | 34 | NO | YES |
CVE-2004-0250HIGH SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat paramete | Nov 23, 2004 | 10.0 | 31 | NO | NO |
CVE-2006-4828HIGH PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter. | Sep 15, 2006 | 7.5 | 30 | NO | YES |
CVE-2005-0272HIGH ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended rest | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-0929HIGH SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo param | May 2, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1629HIGH SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter. | May 17, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0273HIGH Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter. | May 2, 2005 | 7.5 | 28 | NO | YES |
CVE-2004-1870HIGH Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo p | Mar 29, 2004 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Photopost.
Media articles that mention a CVE ID that affects a product developed by Photopost — matched by CVE ID, not by vendor name.