Unrated severityOSV Advisory· Published Dec 15, 2025· Updated Apr 7, 2026
Coppermine Gallery 1.6.25 Remote Code Execution via Plugin Upload
CVE-2023-53868
Description
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Affected products
1- Range: v1.6.04, v1.6.05, v1.6.06, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/51738mitreexploit
- www.vulncheck.com/advisories/coppermine-gallery-remote-code-execution-via-plugin-uploadmitrethird-party-advisory
- web.archive.org/web/20240101151648/https://coppermine-gallery.net/mitreproduct
News mentions
0No linked articles in our index yet.