CVE-2023-53868
Coppermine Gallery 1.6.25 Remote Code Execution via Plugin Upload
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
| CWE | CWE-434 |
| Vendor | coppermine |
| Product | coppermine-gallery |
| Published | Dec 15, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for coppermine coppermine-gallery
Be the first to know when new unknown vulnerabilities affecting coppermine coppermine-gallery are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Coppermine / coppermine-gallery
1.6.25
References
Credits
Mirabbas Ağalarov