CVE-2023-53916: Zenphoto

Medium severity, CVSS 4.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser context.

Affected products

Published 2025-12-17. Last modified 2026-06-17.