Zenphoto

Zenphoto

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 22:44:50
  • Zuletzt bearbeitet 27.12.2025 17:15:43

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 17.12.2025 22:44:50
  • Zuletzt bearbeitet 27.12.2025 17:15:43

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in t...

  • EPSS 0.32%
  • Veröffentlicht 21.12.2022 09:15:08
  • Zuletzt bearbeitet 16.04.2025 18:15:57

Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

Exploit
  • EPSS 23.98%
  • Veröffentlicht 26.02.2021 23:15:11
  • Zuletzt bearbeitet 21.11.2024 05:28:44

Zenphoto through 1.5.7 is affected by authenticated arbitrary file upload, leading to remote code execution. The attacker must navigate to the uploader plugin, check the elFinder box, and then drag and drop files into the Files(elFinder) portion of t...

  • EPSS 0.79%
  • Veröffentlicht 11.06.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:34:19

Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.

  • EPSS 0.35%
  • Veröffentlicht 11.06.2020 08:15:11
  • Zuletzt bearbeitet 21.11.2024 05:34:19

Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vectors.

  • EPSS 0.24%
  • Veröffentlicht 11.02.2020 18:15:15
  • Zuletzt bearbeitet 21.11.2024 01:43:03

Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 31.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 02:33:21

Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).

Exploit
  • EPSS 0.37%
  • Veröffentlicht 31.12.2019 21:15:11
  • Zuletzt bearbeitet 21.11.2024 02:33:21

The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>payload<script></script></scri...

Exploit
  • EPSS 0.7%
  • Veröffentlicht 31.12.2019 21:15:10
  • Zuletzt bearbeitet 21.11.2024 02:33:21

Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.