← Vulnerability feed

Vulnerability record · CVE-2023-53868 · published 15 December 2025

CVE-2023-53868: Coppermine-gallery coppermine photo gallery unrestricted file upload vulnerability

Coppermine Gallery · Coppermine Photo Gallery

Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.

8.7 CVSS 4.0 High EPSS 0.85% · top 43.5% CWE-434 · Unrestricted file upload
8.7CVSS 4.0 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Coppermine Gallery 1.6.25 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files through the plugin manager. Attackers can upload a zipped PHP file with system commands to the plugin directory and execute arbitrary code by accessing the uploaded plugin script.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-53868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2008-3486Coppermine-gallery coppermine photo gallery path traversal vulnerabilityDirectory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier,…EPSS 6.3%7.5CVE-2008-3481Coppermine-gallery coppermine photo gallery code injection vulnerabilitythemes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct req…EPSS 2.1%6.5CVE-2008-0504Coppermine-gallery coppermine photo gallery sql injection vulnerabilityMultiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary…EPSS 2.0%6.1CVE-2018-14478Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.EPSS 0.99%6.1CVE-2014-4612Coppermine-gallery coppermine photo gallery cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the keywords manager (keywordmgr.php) in Coppermine Photo Gallery before 1.5.27 and 1.6.x before 1.6.01 a…EPSS 1.3%5.8CVE-2015-3922Coppermine-gallery coppermine photo gallery vulnerabilityOpen redirect vulnerability in mode.php in Coppermine Photo Gallery before 1.5.36 allows remote attackers to redirect users to arbitrary web sites an…EPSS 2.1%5.0CVE-2015-3923Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.EPSS 2.2%5.0CVE-2012-1614Coppermine-gallery coppermine photo gallery information exposure vulnerabilityCoppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/…EPSS 8.7%

Source: NIST National Vulnerability Database (record CVE-2023-53868), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.