Known Vulnerabilities for products from Photopost

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Photopost".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2008-7088 json Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to execut... Not Provided 2009-08-26 2026-04-23
CVE-2008-0251 json Unrestricted file upload vulnerability in PhotoPost vBGallery before 2.4.2 allows remote attackers to upload and execute arbi... Not Provided 2008-01-12 2026-04-23
CVE-2006-4990 json Multiple PHP remote file inclusion vulnerabilities in PhotoPost allow remote attackers to execute arbitrary PHP code via a UR... 7.5 - HIGH 2006-09-26 2018-10-17
CVE-2006-4828 json PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute a... 7.5 - HIGH 2006-09-15 2018-10-17
CVE-2005-2737 json Cross-site scripting (XSS) vulnerability in PhotoPost PHP Pro 5.1 allows remote attackers to inject arbitrary web script or H... Not Provided 2005-08-30 2025-04-03
CVE-2005-1629 json SQL injection vulnerability in member.php for Photopost PHP Pro allows remote attackers to execute arbitrary SQL commands via... Not Provided 2005-05-17 2025-04-03
CVE-2005-0929 json SQL injection vulnerability in PhotoPost PHP Pro 5.x may allow remote attackers to execute arbitrary SQL commands via (1) the... Not Provided 2005-05-02 2025-04-03
CVE-2005-0928 json Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 5.x allow remote attackers to inject arbitrary web s... Not Provided 2005-05-02 2025-04-03
CVE-2005-0778 json PhotoPost PHP 5.0 RC3 does not fully verify that an uploaded file is an image file, which allows remote attackers to inject a... Not Provided 2005-05-02 2025-04-03
CVE-2005-0777 json Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP 5.0 RC3 allow remote attackers to inject arbitrary web s... Not Provided 2005-05-02 2025-04-03
CVE-2005-0776 json adm-photo.php in PhotoPost PHP 5.0 RC3 does not properly verify administrative privileges before manipulating photos, which c... Not Provided 2005-05-02 2025-04-03
CVE-2005-0775 json The reportpost action in misc.php for PhotoPost PHP 5.0 RC3 does not limit the logging data that is sent to the administrator... Not Provided 2005-05-02 2025-04-03
CVE-2005-0774 json SQL injection vulnerability in member.php and possibly other scripts in PhotoPost PHP 5.0 RC3 allows remote attackers to exec... Not Provided 2005-03-10 2025-04-03
CVE-2005-0274 json Multiple cross-site scripting (XSS) vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to inj... Not Provided 2005-01-03 2025-04-03
CVE-2005-0273 json Multiple SQL injection vulnerabilities in showgallery.php in PhotoPost before 4.86 allow remote attackers to execute arbitrar... Not Provided 2005-05-02 2025-04-03
CVE-2005-0272 json ReviewPost PHP Pro before 2.84 allows remote attackers to upload and execute arbitrary PHP files by posting a review file wit... Not Provided 2005-05-02 2025-04-03
CVE-2005-0271 json Multiple SQL injection vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to execute arbitrary SQL comm... Not Provided 2005-01-03 2025-04-03
CVE-2005-0270 json Multiple cross-site scripting (XSS) vulnerabilities in ReviewPost PHP Pro before 2.84 allow remote attackers to inject arbitr... Not Provided 2005-05-02 2025-04-03
CVE-2004-1871 json Multiple cross-site scripting (XSS) vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to inject a... Not Provided 2004-03-29 2025-04-03
CVE-2004-1870 json Multiple SQL injection vulnerabilities in PhotoPost PHP Pro 4.6.x and earlier allow remote attackers to gain users' passwords... Not Provided 2004-03-29 2025-04-03

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report