Piwigo
Products
5- 108 CVEs
- 9 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
117| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33362 | Cri | 0.67 | 9.8 | 0.09 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | ||
| CVE-2017-10682 | Cri | 0.67 | 9.8 | 0.08 | Jun 29, 2017 | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php. | ||
| CVE-2020-19213 | Cri | 0.65 | 9.8 | 0.16 | May 6, 2022 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. | ||
| CVE-2023-33361 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php. | ||
| CVE-2014-8945 | Cri | 0.64 | 9.8 | 0.02 | Jun 1, 2020 | admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields. | ||
| CVE-2014-8941 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI. | ||
| CVE-2017-9426 | Cri | 0.64 | 9.8 | 0.03 | Feb 26, 2018 | ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action. | ||
| CVE-2019-13364 | Cri | 0.63 | 9.6 | 0.01 | Sep 13, 2019 | admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF. | ||
| CVE-2019-13363 | Cri | 0.63 | 9.6 | 0.01 | Sep 13, 2019 | admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit… | ||
| CVE-2023-26876 | Hig | 0.61 | 8.8 | 0.10 | Apr 21, 2023 | SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint. | ||
| CVE-2026-27634 | Cri | 0.57 | 9.8 | 0.01 | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without… | ||
| CVE-2024-48311 | Hig | 0.57 | 8.8 | 0.00 | Oct 31, 2024 | Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. | ||
| CVE-2023-27233 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2023 | Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php. | ||
| CVE-2021-40553 | Hig | 0.57 | 8.8 | 0.02 | Jun 28, 2022 | piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor. | ||
| CVE-2021-40317 | Hig | 0.57 | 8.8 | 0.01 | May 26, 2022 | Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter. | ||
| CVE-2020-19217 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager. | ||
| CVE-2020-19216 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm. | ||
| CVE-2020-19215 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm. | ||
| CVE-2022-26266 | Hig | 0.57 | 8.8 | 0.01 | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php. | ||
| CVE-2021-40313 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2021 | Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php. |
- risk 0.67cvss 9.8epss 0.09
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
- risk 0.67cvss 9.8epss 0.08
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
- risk 0.65cvss 9.8epss 0.16
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
- risk 0.64cvss 9.8epss 0.01
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
- risk 0.64cvss 9.8epss 0.02
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
- risk 0.64cvss 9.8epss 0.01
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.
- risk 0.64cvss 9.8epss 0.03
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
- risk 0.63cvss 9.6epss 0.01
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
- risk 0.63cvss 9.6epss 0.01
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit…
- risk 0.61cvss 8.8epss 0.10
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
- risk 0.57cvss 9.8epss 0.01
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without…
- risk 0.57cvss 8.8epss 0.00
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
- risk 0.57cvss 8.8epss 0.01
Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php.
- risk 0.57cvss 8.8epss 0.02
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
- risk 0.57cvss 8.8epss 0.01
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
- risk 0.57cvss 8.8epss 0.01
Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.
- risk 0.57cvss 8.8epss 0.01
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.