Piwigo
by Piwigo
Source repositories
CVEs (108)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40678 | Med | 0.35 | 5.4 | 0.00 | Jun 14, 2022 | In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit. | ||
| CVE-2022-24620 | Med | 0.35 | 5.4 | 0.01 | Feb 24, 2022 | Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can steal webmaster's cookies to get the webmaster's access. | ||
| CVE-2020-8089 | Med | 0.35 | 5.4 | 0.01 | Feb 10, 2020 | Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page. | ||
| CVE-2018-7724 | Med | 0.35 | 5.4 | 0.00 | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible. | ||
| CVE-2018-7723 | Med | 0.35 | 5.4 | 0.01 | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-2017-9836. CSRF exploitation, related to CVE-2017-10681, may be possible. | ||
| CVE-2018-7722 | Med | 0.35 | 5.4 | 0.01 | Mar 6, 2018 | The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-10681, may be possible. | ||
| CVE-2016-10514 | Med | 0.35 | 6.5 | 0.01 | Oct 10, 2017 | url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring. | ||
| CVE-2016-10513 | Med | 0.33 | 6.1 | 0.01 | Oct 10, 2017 | Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php. | ||
| CVE-2016-10083 | Med | 0.33 | 6.1 | 0.01 | Dec 30, 2016 | Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case. | ||
| CVE-2020-19212 | Med | 0.32 | 4.9 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete. | ||
| CVE-2018-6883 | Med | 0.32 | 4.9 | 0.01 | Feb 24, 2018 | Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator. | ||
| CVE-2017-17824 | Med | 0.32 | 4.9 | 0.01 | Dec 21, 2017 | The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database. | ||
| CVE-2017-17823 | Med | 0.32 | 4.9 | 0.01 | Dec 21, 2017 | The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database. | ||
| CVE-2017-17822 | Med | 0.32 | 4.9 | 0.01 | Dec 21, 2017 | The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database. | ||
| CVE-2024-46333 | Med | 0.31 | 4.8 | 0.00 | Sep 27, 2024 | An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function. | ||
| CVE-2017-17825 | Med | 0.31 | 4.8 | 0.01 | Dec 21, 2017 | The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it. | ||
| CVE-2017-9836 | Med | 0.31 | 4.8 | 0.01 | Jun 24, 2017 | Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album). | ||
| CVE-2017-9452 | Med | 0.31 | 4.8 | 0.01 | Jun 6, 2017 | Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | ||
| CVE-2014-125053 | Med | 0.29 | 5.5 | 0.01 | Jan 6, 2023 | A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading… | ||
| CVE-2023-34626 | Med | 0.28 | 4.3 | 0.01 | Jun 15, 2023 | Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function. |
- risk 0.35cvss 5.4epss 0.00
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
- risk 0.35cvss 5.4epss 0.01
Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can steal webmaster's cookies to get the webmaster's access.
- risk 0.35cvss 5.4epss 0.01
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
- risk 0.35cvss 5.4epss 0.00
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible.
- risk 0.35cvss 5.4epss 0.01
The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-2017-9836. CSRF exploitation, related to CVE-2017-10681, may be possible.
- risk 0.35cvss 5.4epss 0.01
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-10681, may be possible.
- risk 0.35cvss 6.5epss 0.01
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.
- risk 0.33cvss 6.1epss 0.01
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
- risk 0.33cvss 6.1epss 0.01
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.
- risk 0.32cvss 4.9epss 0.01
SQL Injection vulnerability in admin/group_list.php in piwigo v2.9.5, via the group parameter to delete.
- risk 0.32cvss 4.9epss 0.01
Piwigo before 2.9.3 has SQL injection in admin/tags.php in the administration panel, via the tags array parameter in an admin.php?page=tags request. The attacker must be an administrator.
- risk 0.32cvss 4.9epss 0.01
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database.
- risk 0.32cvss 4.9epss 0.01
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
- risk 0.32cvss 4.9epss 0.01
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter. An attacker can exploit this to gain access to the data in a connected MySQL database.
- risk 0.31cvss 4.8epss 0.00
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.
- risk 0.31cvss 4.8epss 0.01
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it.
- risk 0.31cvss 4.8epss 0.01
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).
- risk 0.31cvss 4.8epss 0.01
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
- risk 0.29cvss 5.5epss 0.01
A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading…
- risk 0.28cvss 4.3epss 0.01
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
Page 4 of 6