Phpwebgallery

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 13
    Known Exploited: 0
    1
    Critical Level Threats
    4
    High Level Threats
    6
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2008-4702

    Multiple directory traversal vulnerabilities in PhpWebGallery 1.3.4 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) user[language] and (2) user[template] parameters to (a) init.inc.php, and (b) the user[language] parameter to isadmin.inc.php.

    Last Modified: Apr 23, 2026
    Published: Oct 22, 2008

    CVE-2008-4645

    plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to execute arbitrary PHP code via PHP sequences in the sort parameter, which is processed by create_function.

    Last Modified: Apr 23, 2026
    Published: Oct 21, 2008

    CVE-2008-4591

    Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) lang[access_forbiden] and (2) lang[ident_title] parameters.

    Last Modified: Apr 23, 2026
    Published: Oct 16, 2008

    CVE-2008-3451

    PhpWebGallery 1.7.0 and 1.7.1 allows remote authenticated users with advisor privileges to obtain the real e-mail addresses of other users by editing the user's profile.

    Last Modified: Apr 23, 2026
    Published: Aug 04, 2008

    CVE-2007-5012

    Cross-site scripting (XSS) vulnerability in picture.php in PhpWebGallery 1.7.0, when Comments for all is enabled, allows remote attackers to inject arbitrary web script or HTML via the author parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Last Modified: Apr 23, 2026
    Published: Sep 20, 2007
    Items Per Page
    Phpwebgallery Vulnerabilities & Security CVEs | CVE-DB