CVE-2026-3013: Coppermine Photo Gallery

High severity, CVSS 8.7. EPSS: 0.7% chance of exploitation in the next 30 days.

Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28.

Affected products

Published 2026-03-11. Last modified 2026-06-17.