VYPR

Piwigo

by Piwigo

Source repositories

CVEs (108)

  • CVE-2021-40678MedJun 14, 2022
    risk 0.35cvss 5.4epss 0.00

    In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

  • CVE-2022-24620MedFeb 24, 2022
    risk 0.35cvss 5.4epss 0.01

    Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can steal webmaster's cookies to get the webmaster's access.

  • CVE-2020-8089MedFeb 10, 2020
    risk 0.35cvss 5.4epss 0.01

    Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.

  • CVE-2018-7724MedMar 6, 2018
    risk 0.35cvss 5.4epss 0.00

    The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible.

  • CVE-2018-7723MedMar 6, 2018
    risk 0.35cvss 5.4epss 0.01

    The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-2017-9836. CSRF exploitation, related to CVE-2017-10681, may be possible.

  • CVE-2018-7722MedMar 6, 2018
    risk 0.35cvss 5.4epss 0.01

    The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-10681, may be possible.

  • CVE-2016-10514MedOct 10, 2017
    risk 0.35cvss 6.5epss 0.01

    url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.

  • CVE-2016-10513MedOct 10, 2017
    risk 0.33cvss 6.1epss 0.01

    Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.

  • CVE-2016-10083MedDec 30, 2016
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.

  • CVE-2020-19212MedMay 6, 2022
    risk 0.32cvss 4.9epss 0.01

    SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.

  • CVE-2018-6883MedFeb 24, 2018
    risk 0.32cvss 4.9epss 0.01

    Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.

  • CVE-2017-17824MedDec 21, 2017
    risk 0.32cvss 4.9epss 0.01

    The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.

  • CVE-2017-17823MedDec 21, 2017
    risk 0.32cvss 4.9epss 0.01

    The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

  • CVE-2017-17822MedDec 21, 2017
    risk 0.32cvss 4.9epss 0.01

    The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.

  • CVE-2024-46333MedSep 27, 2024
    risk 0.31cvss 4.8epss 0.00

    An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.

  • CVE-2017-17825MedDec 21, 2017
    risk 0.31cvss 4.8epss 0.01

    The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.

  • CVE-2017-9836MedJun 24, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).

  • CVE-2017-9452MedJun 6, 2017
    risk 0.31cvss 4.8epss 0.01

    Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

  • CVE-2014-125053MedJan 6, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading…

  • CVE-2023-34626MedJun 15, 2023
    risk 0.28cvss 4.3epss 0.01

    Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.

Page 4 of 6