VYPR
Medium severity5.4NVD Advisory· Published Mar 26, 2020· Updated Jun 17, 2026

CVE-2020-9467

CVE-2020-9467

Description

Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Piwigo/Piwigo2 versions
    cpe:2.3:a:piwigo:piwigo:2.10.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:piwigo:piwigo:2.10.1:*:*:*:*:*:*:*
    • (no CPE)range: 2.10.1
  • Piwigo/Piwigodescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.