Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zenphoto

First CVE: May 4, 2006Active for: 20 yearsTotal CVEs: 33
35.8
VTI Score
Medium

Zenphoto is a self-hosted photo gallery and portfolio application whose vulnerability exposure concentrates in a single, modestly represented product that appeals to photographers and small publishers seeking on-premise image management. The recurring weakness profile—dominated by cross-site scripting, SQL injection, code injection, and cross-site request forgery—reflects the inherent risks of web-based user-input handling and dynamic code generation in gallery and publishing contexts. The vendor's disclosures have a pronounced tendency toward public exploit-code availability, underscoring the accessibility of these web-application flaws to both researchers and adversaries. Defenders deploying this software should prioritize network segmentation and access restrictions, inventory instances carefully, and apply patches promptly given the character of the underlying weakness classes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
2.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
5.9
Avg CVSS Score
Higher Avg CVSS Score than 27% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zenphoto over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 4, 2006
20 years ago
Most Recent CVE
Dec 17, 2025
219 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-4906HIGH
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of thes
Oct 8, 20117.531NOYES
CVE-2015-5591HIGH
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
Dec 31, 20197.229NOYES
CVE-2009-4566HIGH
SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance
Jan 4, 20107.529NOYES
CVE-2007-6666HIGH
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter.
Jan 4, 20087.528NOYES
CVE-2006-2187MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.ph
May 4, 20066.827NOYES
CVE-2015-5595MEDIUM
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may caus
Dec 31, 20196.526NOYES
CVE-2009-4564MEDIUM
SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter
Jan 4, 20106.826NOYES
CVE-2015-5594MEDIUM
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site sc
Jul 25, 20176.125NOYES
CVE-2020-36079HIGH
Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder b
Feb 26, 20217.224NONO
CVE-2018-0610HIGH
Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive informatio
Jun 26, 20187.224NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
76%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (42.4%)
Unknown19 (57.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (42.4%)
High0 (0.0%)
Unknown19 (57.6%)
User Interaction
None4 (12.1%)
Unknown19 (57.6%)
Required10 (30.3%)
Privileges Required
Low3 (9.1%)
High4 (12.1%)
None7 (21.2%)
Unknown19 (57.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zenphoto.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zenphoto — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zenphoto's Products

View all 4 CNAs →

Top CWEs