Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Photopost

First CVE: Mar 29, 2004Active for: 22 yearsTotal CVEs: 22
49.9
VTI Score
TOP TARGET

Photopost maintains a focused line of PHP-based gallery and community-content platforms, including Photopost PHP Pro and ReviewPost PHP Pro, that have achieved notable deployment across web communities and niche hosting environments. While the vendor's disclosures are modest in volume, they recur around input-validation and code-injection weaknesses characteristic of server-side PHP applications handling user-supplied content and templates. The vendor's vulnerability profile is distinguished by a strong tendency toward public exploit availability, reflecting the appeal of these platforms to both attackers developing proof-of-concept tooling and operators of legacy web properties seeking to understand exposure. Defenders managing instances of these products should prioritize patching cycles and restrict administrative interfaces, as older versions remain in service across distributed hosting and remain targets for reconnaissance and lateral movement. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Photopost over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 29, 2004
22 years ago
Most Recent CVE
Aug 26, 2009
6,178 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-0251HIGH
Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbitrary files via unknown vectors.
Jan 12, 200810.036NOYES
CVE-2004-0239HIGH
SQL injection vulnerability in showphoto.php in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain unauthorized access via the photo variable.
Nov 23, 200410.035NOYES
CVE-2005-0271HIGH
Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL commands via the (1) cat parameter to showcat.php or (2) pr
Jan 3, 20057.534NOYES
CVE-2004-0250HIGH
SQL injection vulnerability in PhotoPost PHP Pro 4.6 and earlier allows remote attackers to gain privileges via (1) the product parameter in showproduct.php or (2) the cat paramete
Nov 23, 200410.031NONO
CVE-2006-4828HIGH
PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.
Sep 15, 20067.530NOYES
CVE-2005-0272HIGH
ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file with multiple extensions, which bypasses the intended rest
May 2, 20057.529NOYES
CVE-2005-0929HIGH
SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the sl parameter to showmembers.php or (2) the photo param
May 2, 20057.529NOYES
CVE-2005-1629HIGH
SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via the verifykey parameter.
May 17, 20057.528NOYES
CVE-2005-0273HIGH
Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrary SQL commands via the (1) cat or (2) ppuser parameter.
May 2, 20057.528NOYES
CVE-2004-1870HIGH
Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords via the (1) photo parameter to addfav.php, (2) photo p
Mar 29, 20047.528NOYES
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
41%
59%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown22 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown22 (100.0%)
User Interaction
None0 (0.0%)
Unknown22 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown22 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
15 CVEs
68.2% of CVEs· 84th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Photopost.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Photopost — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Photopost's Products

View all 1 CNAs →

Top CWEs