CVE-2023-53916

MEDIUM

Zenphoto 1.6 - XSS

Title source: llm

Description

Zenphoto 1.6 contains a stored cross-site scripting vulnerability in the user postal code field accessible through the admin-users.php interface. When administrators view user information imported as HTML, malicious JavaScript payloads injected into the postal code field execute in their browser context.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Mirabbas Ağalarov · textwebappsphp
https://www.exploit-db.com/exploits/51485

Scores

CVSS v3 4.6
EPSS 0.0005
EPSS Percentile 14.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (2)
zenphoto/zenphoto 1.6
Zenphoto/Zenphoto 1.6
Published Dec 17, 2025
Tracked Since Feb 18, 2026