Zenphoto is a self-hosted photo gallery and portfolio application whose vulnerability exposure concentrates in a single, modestly represented product that appeals to photographers and small publishers seeking on-premise image management. The recurring weakness profile—dominated by cross-site scripting, SQL injection, code injection, and cross-site request forgery—reflects the inherent risks of web-based user-input handling and dynamic code generation in gallery and publishing contexts. The vendor's disclosures have a pronounced tendency toward public exploit-code availability, underscoring the accessibility of these web-application flaws to both researchers and adversaries. Defenders deploying this software should prioritize network segmentation and access restrictions, inventory instances carefully, and apply patches promptly given the character of the underlying weakness classes. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Zenphoto over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-4906HIGH SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arbitrary SQL commands via the a parameter. NOTE: some of thes | Oct 8, 2011 | 7.5 | 31 | NO | YES |
CVE-2015-5591HIGH SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands. | Dec 31, 2019 | 7.2 | 29 | NO | YES |
CVE-2009-4566HIGH SQL injection vulnerability in index.php in Zenphoto 1.2.5 allows remote attackers to execute arbitrary SQL commands via the title parameter in a news action. NOTE: the provenance | Jan 4, 2010 | 7.5 | 29 | NO | YES |
CVE-2007-6666HIGH SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL commands via the albumnr parameter. | Jan 4, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-2187MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.ph | May 4, 2006 | 6.8 | 27 | NO | YES |
CVE-2015-5595MEDIUM Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may caus | Dec 31, 2019 | 6.5 | 26 | NO | YES |
CVE-2009-4564MEDIUM SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter | Jan 4, 2010 | 6.8 | 26 | NO | YES |
CVE-2015-5594MEDIUM The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site sc | Jul 25, 2017 | 6.1 | 25 | NO | YES |
CVE-2020-36079HIGH Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder b | Feb 26, 2021 | 7.2 | 24 | NO | NO |
CVE-2018-0610HIGH Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive informatio | Jun 26, 2018 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Zenphoto.
Media articles that mention a CVE ID that affects a product developed by Zenphoto — matched by CVE ID, not by vendor name.