CVE-2026-3013

Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Mar 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-11 15:16

Updated : 2026-03-12 21:08


NVD link : CVE-2026-3013

Mitre link : CVE-2026-3013

CVE.ORG link : CVE-2026-3013


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')