CVE-2026-3013: Coppermine Photo Gallery
High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.
Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28.
Affected products
- Coppermine Photo Gallery Coppermine Photo Gallery: from 1.6.09, before 1.6.28 (fixed in 1.6.28)
Published 2026-03-11. Last modified 2026-06-17.