Xeroxer maintains a simple, single-file gallery application with a narrow product scope. The observed vulnerability surface reflects application-level concerns typical of file-handling and web-presentation code. Current vulnerability counts, severity breakdown, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Xeroxer over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1124MEDIUM Directory traversal vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to read arbitrary files via a .. (dot dot) in the f parameter. | Feb 27, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-1125MEDIUM Cross-site scripting (XSS) vulnerability in gallery.php in XeroXer Simple one-file gallery allows remote attackers to inject arbitrary web script or HTML via the f parameter. | Feb 27, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Xeroxer.
Media articles that mention a CVE ID that affects a product developed by Xeroxer — matched by CVE ID, not by vendor name.