CVE-2022-44449: Zenphoto

Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.

Affected products

  • Zenphoto Zenphoto: before 1.6 (fixed in 1.6)

Published 2022-12-21. Last modified 2026-06-17.