VYPR

Cpg1.6.x

by Coppermine

Source repositories

CVEs (4)

  • CVE-2026-3013HigMar 11, 2026
    risk 0.57cvss —epss 0.01

    Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue…

  • CVE-2023-53868HigDec 15, 2025
    risk 0.57cvss 8.8epss 0.01

    Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code…

  • CVE-2026-82483LowAug 30, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This impacts an unknown function of the file db_input.php of the component Hidden Album Update Endpoint. The manipulation results in cross site scripting. The attack can be launched…

  • CVE-2026-82482LowAug 30, 2026
    risk 0.16cvss 3.5epss 0.00

    A security vulnerability has been detected in coppermine-gallery Coppermine Photo Gallery up to 1.6.28. This affects an unknown function of the file profile.php of the component edit_profile Endpoint. The manipulation of the argument Biography leads to cross site scripting. The…