VYPR

Piwigo

by Piwigo

Source repositories

CVEs (108)

  • CVE-2017-10681HigJun 29, 2017
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.

  • CVE-2017-10680HigJun 29, 2017
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.

  • CVE-2017-10678HigJun 29, 2017
    risk 0.57cvss 8.8epss 0.01

    Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.

  • CVE-2016-10105CriJan 3, 2017
    risk 0.57cvss 9.8epss 0.02

    admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence.

  • CVE-2021-27973HigApr 2, 2021
    risk 0.51cvss 7.2epss 0.11

    SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

  • CVE-2022-32297HigJul 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.

  • CVE-2022-26267HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.01

    Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.

  • CVE-2017-10679HigJun 29, 2017
    risk 0.49cvss 7.5epss 0.02

    Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.

  • CVE-2016-3735HigJan 28, 2022
    risk 0.46cvss 8.1epss 0.01

    Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed used to generate it. This low an unauthenticated attacker…

  • CVE-2014-4613MedMar 16, 2018
    risk 0.46cvss 6.5epss 0.03

    Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.

  • CVE-2026-27833HigApr 3, 2026
    risk 0.42cvss 7.5epss 0.02

    Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This…

  • CVE-2024-43018MedJul 29, 2025
    risk 0.42cvss 6.4epss 0.00

    Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for…

  • CVE-2017-16893MedDec 1, 2017
    risk 0.42cvss 6.5epss 0.01

    The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database.…

  • CVE-2017-9463MedJun 14, 2017
    risk 0.42cvss 6.5epss 0.02

    The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The…

  • CVE-2026-27885HigApr 3, 2026
    risk 0.40cvss 7.2epss 0.00

    Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the…

  • CVE-2026-27834HigApr 3, 2026
    risk 0.40cvss 7.2epss 0.00

    Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing…

  • CVE-2024-46605MedOct 16, 2024
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.

  • CVE-2023-51790MedJan 12, 2024
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

  • CVE-2022-37183MedAug 31, 2022
    risk 0.40cvss 6.1epss 0.01

    Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.

  • CVE-2021-45357MedFeb 10, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.php.

Page 2 of 6