CVE-2018-0610: Zenphoto

High severity, CVSS 7.2. EPSS: 1.8% chance of exploitation in the next 30 days.

Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.

Affected products

  • Zenphoto Zenphoto: up to and including 1.4.14

Published 2018-06-26. Last modified 2026-06-17.