📦 Zenphoto

by Zenphoto

🔍 What is Zenphoto?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2020-36079

HIGH CVSS 7.2 Feb 26, 2021

Zenphoto CMS versions through 1.5.7 allow authenticated administrators to upload arbitrary files, including PHP web shells, leading to remote code execution. This affects all Zenphoto installations wi...

CVE-2020-5593

HIGH CVSS 8.8 Jun 11, 2020

CVE-2020-5593 is a PHP code injection vulnerability in Zenphoto CMS that allows attackers to execute arbitrary code by tricking users into uploading malicious .zip files. This affects all Zenphoto ins...

CVE-2023-53915

MEDIUM CVSS 4.6 Dec 17, 2025

Zenphoto 1.6 contains a stored cross-site scripting vulnerability where authenticated attackers can inject malicious HTML/JavaScript into album descriptions. When users view affected album pages, the ...

CVE-2023-53916

MEDIUM CVSS 4.6 Dec 17, 2025

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field. When administrators view user information, malicious JavaScript injected into postal code fields execut...