Vulnerabilities (CVE)

Filtered by vendor Zenphoto Subscribe
Filtered by product Zenphoto
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5592 1 Zenphoto 1 Zenphoto 2020-06-15 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vectors.
CVE-2012-4519 1 Zenphoto 1 Zenphoto 2020-02-12 4.3 MEDIUM 6.1 MEDIUM
Zenphoto before 1.4.3.4 admin-news-articles.php date parameter XSS.
CVE-2015-5595 1 Zenphoto 1 Zenphoto 2020-01-07 4.3 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of service (resource consumption).
CVE-2015-5593 1 Zenphoto 1 Zenphoto 2020-01-07 4.3 MEDIUM 6.1 MEDIUM
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<script></script>script>payload<script></script></script>", or in an image tag, with the payload as the onerror event.
CVE-2015-5592 1 Zenphoto 1 Zenphoto 2020-01-07 4.3 MEDIUM 6.1 MEDIUM
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
CVE-2018-20140 1 Zenphoto 1 Zenphoto 2019-03-21 4.3 MEDIUM 6.1 MEDIUM
Zenphoto 1.4.14 has multiple cross-site scripting (XSS) vulnerabilities via different URL parameters.
CVE-2015-5594 1 Zenphoto 1 Zenphoto 2017-07-31 4.3 MEDIUM 6.1 MEDIUM
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.