Piwigo
by Piwigo
Source repositories
CVEs (108)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40882 | Med | 0.40 | 6.1 | 0.01 | Dec 14, 2021 | A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location. | ||
| CVE-2020-22150 | Med | 0.40 | 6.1 | 0.01 | Jul 21, 2021 | A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML. | ||
| CVE-2020-22148 | Med | 0.40 | 6.1 | 0.01 | Jul 21, 2021 | A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML. | ||
| CVE-2020-9467 | Med | 0.40 | 5.4 | 0.24 | Mar 26, 2020 | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. | ||
| CVE-2012-4526 | Med | 0.40 | 6.1 | 0.01 | Dec 2, 2019 | piwigo has XSS in password.php (incomplete fix for CVE-2012-4525) | ||
| CVE-2012-4525 | Med | 0.40 | 6.1 | 0.01 | Dec 2, 2019 | piwigo has XSS in password.php | ||
| CVE-2017-9425 | Med | 0.40 | 6.1 | 0.01 | Feb 26, 2018 | The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action. | ||
| CVE-2018-5692 | Med | 0.40 | 6.1 | 0.01 | Jan 14, 2018 | Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file. | ||
| CVE-2017-17826 | Med | 0.40 | 6.1 | 0.01 | Dec 21, 2017 | The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it. | ||
| CVE-2017-17775 | Med | 0.40 | 6.1 | 0.01 | Dec 20, 2017 | Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request. | ||
| CVE-2017-9464 | Med | 0.40 | 6.1 | 0.01 | Jun 14, 2017 | An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not… | ||
| CVE-2017-5608 | Med | 0.40 | 6.1 | 0.01 | Jan 28, 2017 | Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename. | ||
| CVE-2016-10085 | Hig | 0.40 | 7.2 | 0.02 | Dec 30, 2016 | admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter. | ||
| CVE-2016-10084 | Hig | 0.40 | 7.2 | 0.02 | Dec 30, 2016 | admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter). | ||
| CVE-2016-9751 | Med | 0.40 | 6.1 | 0.01 | Dec 1, 2016 | Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | ||
| CVE-2025-62512 | Med | 0.35 | 5.3 | 0.01 | Feb 24, 2026 | Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The… | ||
| CVE-2024-52701 | Med | 0.35 | 5.4 | 0.00 | Nov 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter. | ||
| CVE-2024-46606 | Med | 0.35 | 5.4 | 0.00 | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | ||
| CVE-2024-26450 | Med | 0.35 | 5.4 | 0.00 | Feb 28, 2024 | An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing… | ||
| CVE-2022-48007 | Med | 0.35 | 5.4 | 0.00 | Jan 27, 2023 | A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User-Agent. |
- risk 0.40cvss 6.1epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.
- risk 0.40cvss 6.1epss 0.01
A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
- risk 0.40cvss 6.1epss 0.01
A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
- risk 0.40cvss 5.4epss 0.24
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
- risk 0.40cvss 6.1epss 0.01
piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)
- risk 0.40cvss 6.1epss 0.01
piwigo has XSS in password.php
- risk 0.40cvss 6.1epss 0.01
The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.
- risk 0.40cvss 6.1epss 0.01
Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.
- risk 0.40cvss 6.1epss 0.01
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
- risk 0.40cvss 6.1epss 0.01
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
- risk 0.40cvss 6.1epss 0.01
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks. The identification.php component is affected by this issue: the "redirect" parameter is not…
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename.
- risk 0.40cvss 7.2epss 0.02
admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.
- risk 0.40cvss 7.2epss 0.02
admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] variable (aka the mode parameter).
- risk 0.40cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.
- risk 0.35cvss 5.3epss 0.01
Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The…
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter.
- risk 0.35cvss 5.4epss 0.00
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
- risk 0.35cvss 5.4epss 0.00
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing…
- risk 0.35cvss 5.4epss 0.00
A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the User-Agent.
Page 3 of 6