CVE-2015-5594: Zenphoto
Medium severity, CVSS 6.1. EPSS: 1.9% chance of exploitation in the next 30 days.
The sanitize_string function in ZenPhoto before 1.4.9 utilized the html_entity_decode function after input sanitation, which might allow remote attackers to perform a cross-site scripting (XSS) via a crafted string.
Affected products
- Zenphoto Zenphoto: up to and including 1.4.8
Published 2017-07-25. Last modified 2026-06-17.