Vulnerabilities (CVE)

Filtered by vendor Menalto Subscribe
Total 23 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-2724 1 Menalto 1 Gallery 2025-04-09 5.0 MEDIUM N/A
Menalto Gallery before 2.2.5 does not enforce permissions for non-album items that have been protected by a password, which might allow remote attackers to bypass intended access restrictions.
CVE-2007-6686 1 Menalto 1 Gallery 2025-04-09 10.0 HIGH N/A
The URL rewrite module in Menalto Gallery before 2.2.4 allows attackers to include and execute arbitrary local files via unknown vectors related to the admin controller.
CVE-2008-2723 1 Menalto 1 Gallery 2025-04-09 5.0 MEDIUM N/A
embed.php in Menalto Gallery before 2.2.5 allows remote attackers to obtain the full path via unknown vectors related to "spoofing the remote address."