CVE-2023-53915
Zenphoto 1.6 Stored Cross-Site Scripting via Album Description
CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
0th
Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view the album page.
| CWE | CWE-79 |
| Vendor | zenphoto |
| Product | zenphoto |
| Published | Dec 17, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for zenphoto zenphoto
Be the first to know when new medium vulnerabilities affecting zenphoto zenphoto are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
Zenphoto / Zenphoto
1.6
References
Credits
Mirabbas Ağalarov