CVE-2012-0994: Zenphoto

Medium severity, CVSS 6.0. EPSS: 1.1% chance of exploitation in the next 30 days.

SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.

Affected products

Published 2012-02-21. Last modified 2026-06-16.