Yapig is a modestly represented vendor in the landscape, with a focused product footprint centered on a single platform that has drawn attention relative to its disclosure volume. Its vulnerability profile recurs around code injection and unsafe file-handling practices, reflecting input-validation and upload-control weaknesses characteristic of dynamic application frameworks, and these weaknesses have acquired public exploit code at a notable rate. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yapig over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1882HIGH PHP remote file inclusion vulnerability in last_gallery.php in YaPiG 0.93u and 0.94u allows remote attackers to execute arbitrary PHP code via the YAPIG_PATH parameter. | Jun 9, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1881HIGH upload.php in YaPiG 0.92b, 0.93u and 0.94u does not properly restrict the file extension for uploaded image files, which allows remote attackers to upload arbitrary files and execu | Jun 6, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-1884MEDIUM Directory traversal vulnerability in the (1) rmdir or (2) mkdir commands in upload.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to create or delete arbitrary directo | Jun 9, 2005 | 6.4 | 26 | NO | YES |
CVE-2005-4799MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) | Dec 31, 2005 | 5.1 | 25 | NO | YES |
CVE-2005-4800HIGH Direct static code injection vulnerability in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allows remote authenticated administrators to inject arbitrary PHP code via th | Dec 31, 2005 | 9.0 | 23 | NO | NO |
CVE-2006-4421MEDIUM Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG) 0.95b allows remote attackers to inject arbitrary web scrip | Aug 29, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-1886MEDIUM Cross-site scripting (XSS) vulnerability in view.php in YaPiG 0.92b, 0.93u and 0.94u allows remote attackers to inject arbitrary web script or HTML via (1) the phid parameter or (2 | Jun 9, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-4801HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Yet Another PHP Image Gallery (YaPIG) 0.95b and earlier allow remote attackers to perform unauthorized actions as a lo | Dec 31, 2005 | 7.5 | 19 | NO | NO |
CVE-2007-4951MEDIUM PHP remote file inclusion vulnerability in sample.php in YaPiG 0.95b allows remote attackers to execute arbitrary PHP code via a URL in the YAPIG_PATH parameter. NOTE: this issue | Sep 18, 2007 | 6.8 | 18 | NO | NO |
CVE-2005-1883MEDIUM global.php in YaPiG 0.92b allows remote attackers to include arbitrary local files via the BASE_DIR parameter. | Jun 9, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yapig.
Media articles that mention a CVE ID that affects a product developed by Yapig — matched by CVE ID, not by vendor name.