CVE-2012-0994: Zenphoto
Medium severity, CVSS 6.0. EPSS: 1.1% chance of exploitation in the next 30 days.
SQL injection vulnerability in the Manage Albums feature in zp-core/admin-albumsort.php in ZENphoto 1.4.2 allows remote authenticated users to execute arbitrary SQL commands via the sortableList parameter.
Affected products
- Zenphoto Zenphoto: version 1.4.2 only
Published 2012-02-21. Last modified 2026-06-16.