Phpwebgallery is a web-based photo gallery application where vulnerabilities cluster around input handling and output encoding issues characteristic of server-side web applications. The recurring weakness classes include cross-site scripting, code injection, path traversal, and information disclosure, reflecting the application's exposure to untrusted user input and file-system access patterns, and public exploit code availability is notable for this vendor's disclosures. Defenders should treat input-validation and authentication weaknesses in this gallery platform as patching priorities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpwebgallery over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4645HIGH plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parame | Oct 22, 2008 | 9.0 | 35 | NO | YES |
CVE-2005-4228HIGH Multiple SQL injection vulnerabilities in PhpWebGallery 1.5.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) since, (2) sort_by, and (3) items_num | Dec 14, 2005 | 7.5 | 29 | NO | YES |
CVE-2008-4702HIGH Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) user[language] | Oct 22, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4591MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1 | Oct 16, 2008 | 4.3 | 21 | NO | YES |
CVE-2006-3476MEDIUM Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via | Jul 10, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-1600HIGH SQL injection vulnerability in category.php in PhpWebGallery 1.4.1 allows remote attackers to execute arbitrary SQL commands via the search parameter. | Apr 3, 2006 | 7.5 | 19 | NO | NO |
CVE-2002-2064HIGH isadmin.php in PhpWebGallery 1.0 allows remote attackers to gain administrative access via by setting the photo_login cookie to pseudo. | Dec 31, 2002 | 7.5 | 19 | NO | NO |
Multiple cross-site scripting (XSS) vulnerabilities in PHPWebGallery 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) num, and (3) search pa | Apr 10, 2006 | 2.6 | 18 | NO | YES |
CVE-2006-2041MEDIUM PhpWebGallery before 1.6.0RC1 allows remote attackers to obtain arbitrary pictures via a request to picture.php without specifying the cat parameter. NOTE: the provenance of this | Apr 26, 2006 | 5.0 | 15 | NO | NO |
CVE-2008-3451MEDIUM PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile. | Aug 4, 2008 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpwebgallery.
Media articles that mention a CVE ID that affects a product developed by Phpwebgallery — matched by CVE ID, not by vendor name.