- EPSS 0.2%
- Veröffentlicht 30.08.2026 08:00:08
- Zuletzt bearbeitet 31.08.2026 20:56:08
A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The a...
- EPSS 0.2%
- Veröffentlicht 30.08.2026 06:15:07
- Zuletzt bearbeitet 01.09.2026 14:17:45
A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads ...
CVE-2023-53868
- EPSS 0.83%
- Veröffentlicht 15.12.2025 20:22:36
- Zuletzt bearbeitet 18.12.2025 22:35:06
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory...
CVE-2018-14478
- EPSS 0.99%
- Veröffentlicht 07.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:49:10
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
CVE-2014-4612
- EPSS 1.33%
- Veröffentlicht 16.03.2018 17:29:00
- Zuletzt bearbeitet 21.11.2024 02:10:34
Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2015-6528
- EPSS 1.48%
- Veröffentlicht 20.08.2015 20:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple cross-site scripting (XSS) vulnerabilities in install_classic.php in Coppermine Photo Gallery (CPG) 1.5.36 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_username, (2) admin_password, (3) admin_email, (4) dbs...
- EPSS 2.26%
- Veröffentlicht 10.06.2015 18:59:05
- Zuletzt bearbeitet 06.05.2026 22:30:45
Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.
CVE-2015-3922
- EPSS 2.08%
- Veröffentlicht 27.05.2015 18:59:01
- Zuletzt bearbeitet 06.05.2026 22:30:45
Open redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the referer parameter.
CVE-2015-3921
- EPSS 1.55%
- Veröffentlicht 27.05.2015 18:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Cross-site scripting (XSS) vulnerability in contact.php in Coppermine Photo Gallery before 1.5.36 allows remote authenticated users to inject arbitrary web script or HTML via the referer parameter.
CVE-2012-1613
- EPSS 2.19%
- Veröffentlicht 04.09.2012 20:55:01
- Zuletzt bearbeitet 16.06.2026 23:39:51
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter.