← Vulnerability feed

Vulnerability record · CVE-2014-4612 · published 16 March 2018

CVE-2014-4612: Coppermine-gallery coppermine photo gallery cross-site scripting vulnerability

Coppermine Gallery · Coppermine Photo Gallery

Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

6.1 CVSS 3.0 Medium EPSS 1.3% · top 30.6% CWE-79 · Cross-site scripting
6.1CVSS 3.0 base score, v2 4.3
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-4612 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2023-53868Coppermine-gallery coppermine photo gallery unrestricted file upload vulnerabilityCoppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through th…EPSS 0.85%7.5CVE-2008-3486Coppermine-gallery coppermine photo gallery path traversal vulnerabilityDirectory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier,…EPSS 6.3%7.5CVE-2008-3481Coppermine-gallery coppermine photo gallery code injection vulnerabilitythemes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct req…EPSS 2.1%6.5CVE-2008-0504Coppermine-gallery coppermine photo gallery sql injection vulnerabilityMultiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary…EPSS 2.0%6.1CVE-2018-14478Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.EPSS 0.99%5.8CVE-2015-3922Coppermine-gallery coppermine photo gallery vulnerabilityOpen redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites an…EPSS 2.1%5.0CVE-2015-3923Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.EPSS 2.2%5.0CVE-2012-1614Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/…EPSS 8.7%

Source: NIST National Vulnerability Database (record CVE-2014-4612), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.