Home

Description

Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28.

PUBLISHED Reserved 2026-02-23 | Published 2026-03-11 | Updated 2026-03-11 | Assigner CERT-PL




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

1.6.09 (semver) before 1.6.28
affected

Credits

Jan Paweł Klim finder

References

cert.pl/en/posts/2026/03/CVE-2026-3013

github.com/coppermine-gallery/cpg1.6.x/releases/tag/v1.6.28

cve.org (CVE-2026-3013)

nvd.nist.gov (CVE-2026-3013)

Download JSON