CVE-2023-53868: Coppermine-Gallery Coppermine Photo Gallery
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.
Affected products
- Coppermine-Gallery Coppermine Photo Gallery: version 1.6.25 only
Published 2025-12-15. Last modified 2026-06-17.