High severity8.8OSV Advisory· Published Dec 15, 2025· Updated Jun 17, 2026
CVE-2023-53868
CVE-2023-53868
Description
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: v1.6.04, v1.6.05, v1.6.06, …
cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.6.25:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:coppermine-gallery:coppermine_photo_gallery:1.6.25:*:*:*:*:*:*:*
- (no CPE)range: <1.6.25
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/51738nvdExploitThird Party Advisory
- www.vulncheck.com/advisories/coppermine-gallery-remote-code-execution-via-plugin-uploadnvdThird Party Advisory
- web.archive.org/web/20240101151648/https://coppermine-gallery.net/nvdProduct
News mentions
0No linked articles in our index yet.