Zenphoto 1.4.11

This is a bugfix and security update.


  • Fix some XSS and LFI issues on the backend [acrylian, trisweb – Special thanks to John Page aka hyp3rlinx]
  • Fix wrong number of un-published images in Gallery statistics [fretzl, acrylian]
  • Fix wrong order display in image/album search date archives if sorting was set to "title" [acrylian]
  • Fix dymanic album issue that could result in inability to rename titles etc. [acrylian]
  • Fixes issue with image watermarks if Imagick is enabled [fretzl, acrylian]


  • basic: Some formatting [fretzl]
  • zenpage and zpmobile: Correctly display language flags or language select dropdown  [fretzl]


  • security_logger: Removes really bad logging of failed logon attempt passwords in (...)

Zenphoto 1.4.10

This is a bugfix release.

  • Accidentally some PHP 5.4+ only syntax sneaked in that broke Zenphoto with older PHP versions. However, we encourage using newer PHP versions. Zenphoto is generally tested up to PHP 5.6 currently [acrylian – Thanks to vincent3569]
  • Fixes MySQL errors with search results or image order set to publish order (actually fixes a former a bit too premature fix) [acrylian, fretzl]
  • user groups and user prime album: User prime albums are not removed from the managed album list anymore if not part of the managed albums of the user's group; Creating prime album also does not remove albums from other users' managed album lists [acrylian, fretzl]
  • Fixes sorting of multilingual content fields [sphoto]
  • Zenphoto does not check or set the server session save path anymore. As reported several (...)


A Zenphoto plugin to add a cookie notify dialog to comply with the EU cookie law and Google's requirement for Google Ads and more. More info on that on

Adapted from

Available in following languages:

  • English (native)
  • Dutch (Thanks to fretzl)
  • German

More translations welcome. Instructions here:


New in the showcase gallery: Paranormal Database

We are actually down-to-earth ourselves but here we have a spooky Zenphoto site ;-):



An extension of the original XMP meta data plugin to support importing facial recognition tags embedded by Facebook and others.

Note: Direct external download link!

Zenphoto 1.4.9

This is a security and bugfix release. 


  • Fixes several SQL Injection, XSS and path traversal security issues [trisweb – Thanks to Tim Coen for the report and help]
  • Fixes issue with single image edit page if accessing via front end admin toolbox and "back" button to bulk edit page [trisweb, acrylian – Thanks to MarkRH]
  • Fixes the zenphoto package file which caused an unnecessary file warning on running setup [acrylian - Thanks to vincent3569]
  • Fixes function getNotViewableImages() that failed to exclude said images, e.g. used if "check tag access" for tag lists if tag_suggest is enabled [amalani]
  • Fixes wrong image/album search result order by title [acrylian]

Small change for theme breadcrumbs

Normally on basic themes the gallery index is the same as the site index ( = home page). But on themes (...)

New in the showcase gallery: Matt Botwood Photography

Although basically just using a customisation of the "basic" theme the site looks quite individual:

Matt Botwood Photography

10th Anniversary


Photo: Frank Vincentz – CC-BY-SA

Around ten years and a few months ago, I was sitting in my college dorm room, looking for a way to host my photos on my web site in an elegant way. There were a few projects around, but none of them were quite right for my needs. Out of that problem, some feedback-gathering blog posts, and some late nights of coding, Zenphoto was born, with version 0.1 released ten years ago as of yesterday.

Since then, Zenphoto has grown bigger and more widespread than I thought possible, with hundreds of thousands of installations, over 1.4 million pages linking to, 75,000 forum (...)

Zenphoto 1.4.8

This is a security and bugfix release for some issues that unfortunately sneaked in. As usual this release is recommend for all users.

It is also recommend to users of the zpBase theme because it is directly affected by the print_album_menu bug listed below.


  • Fixes security issue related to the image processor. [trisweb – Thanks to JPCERT]
  • Fixes automatic image cache rebuild on rather rare occasions [davosmith]
  • Fixes bug with album statisticcs in the backend Gallery statistics [acrylian – Thanks to MarkRH]
  • Image rotation bugs fixed [fretzl – Thanks to unrealdtc]
  • Fixes bug accessing the wrong single image edit via the admin toolbox [acrylian - Thanks to MarkRH]
  • Dynamic album creation directly on the backend without prior front end search [acrylian]
  • Fixes wrong html in admin toolbox (...)

3rd party Paradigm theme updated to version 1.0

Our user Olivier Ffrench has just released an update to his theme:

You find screenshots on our themes section and additionally his own site is a demo of it.