CVE-2026-3013
Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal. Unauthenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow to read content of any file accessible by the the web server process.This issue was fixed in version 1.6.28.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://cert.pl/en/posts/2026/03/CVE-2026-3013, https://github.com/coppermine-gallery/cpg1.6.x/releases/tag/v1.6.28
