CVE-2022-44449: Zenphoto
Medium severity, CVSS 4.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Stored cross-site scripting vulnerability in Zenphoto versions prior to 1.6 allows remote a remote authenticated attacker with an administrative privilege to inject an arbitrary script.
Affected products
- Zenphoto Zenphoto: before 1.6 (fixed in 1.6)
Published 2022-12-21. Last modified 2026-06-17.