CVE-2023-53915

MEDIUM

Zenphoto 1.6 - XSS

Title source: llm

Description

Zenphoto 1.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting HTML content into album descriptions. Attackers can create albums with malicious iframe or script tags in the description field that execute when users view the album page.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51485

Scores

CVSS v3 4.6
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
zenphoto/zenphoto 1.6
Zenphoto/Zenphoto 1.6
Published Dec 17, 2025
Tracked Since Feb 18, 2026