Vendor CVEs
Piwigo
All CVEs
117 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-33362 | Cri | 0.67 | 9.8 | 0.09 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | ||
| CVE-2017-10682 | Cri | 0.67 | 9.8 | 0.08 | Jun 29, 2017 | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php. | ||
| CVE-2020-19213 | Cri | 0.65 | 9.8 | 0.16 | May 6, 2022 | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. | ||
| CVE-2023-33361 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php. | ||
| CVE-2014-8945 | Cri | 0.64 | 9.8 | 0.02 | Jun 1, 2020 | admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields. | ||
| CVE-2014-8941 | Cri | 0.64 | 9.8 | 0.01 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI. | ||
| CVE-2017-9426 | Cri | 0.64 | 9.8 | 0.03 | Feb 26, 2018 | ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action. | ||
| CVE-2019-13364 | Cri | 0.63 | 9.6 | 0.01 | Sep 13, 2019 | admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF. | ||
| CVE-2019-13363 | Cri | 0.63 | 9.6 | 0.01 | Sep 13, 2019 | admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit… | ||
| CVE-2023-26876 | Hig | 0.61 | 8.8 | 0.10 | Apr 21, 2023 | SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint. | ||
| CVE-2026-27634 | Cri | 0.57 | 9.8 | 0.01 | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without… | ||
| CVE-2024-48311 | Hig | 0.57 | 8.8 | 0.00 | Oct 31, 2024 | Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. | ||
| CVE-2023-27233 | Hig | 0.57 | 8.8 | 0.01 | May 17, 2023 | Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php. | ||
| CVE-2021-40553 | Hig | 0.57 | 8.8 | 0.02 | Jun 28, 2022 | piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor. | ||
| CVE-2021-40317 | Hig | 0.57 | 8.8 | 0.01 | May 26, 2022 | Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter. | ||
| CVE-2020-19217 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager. | ||
| CVE-2020-19216 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm. | ||
| CVE-2020-19215 | Hig | 0.57 | 8.8 | 0.01 | May 6, 2022 | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm. | ||
| CVE-2022-26266 | Hig | 0.57 | 8.8 | 0.01 | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php. | ||
| CVE-2021-40313 | Hig | 0.57 | 8.8 | 0.01 | Dec 6, 2021 | Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php. | ||
| CVE-2014-8943 | Hig | 0.57 | 8.8 | 0.01 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter. | ||
| CVE-2014-8942 | Hig | 0.57 | 8.8 | 0.00 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows CSRF. | ||
| CVE-2017-17827 | Hig | 0.57 | 8.8 | 0.01 | Dec 21, 2017 | Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions. | ||
| CVE-2017-17774 | Hig | 0.57 | 8.8 | 0.01 | Dec 20, 2017 | admin/configuration.php in Piwigo 2.9.2 has CSRF. | ||
| CVE-2017-10681 | Hig | 0.57 | 8.8 | 0.01 | Jun 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request. | ||
| CVE-2017-10680 | Hig | 0.57 | 8.8 | 0.01 | Jun 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request. | ||
| CVE-2017-10678 | Hig | 0.57 | 8.8 | 0.01 | Jun 29, 2017 | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request. | ||
| CVE-2016-10105 | Cri | 0.57 | 9.8 | 0.02 | Jan 3, 2017 | admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence. | ||
| CVE-2021-27973 | Hig | 0.51 | 7.2 | 0.11 | Apr 2, 2021 | SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages. | ||
| CVE-2014-8938 | Hig | 0.51 | 7.8 | 0.00 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line. | ||
| CVE-2022-32297 | Hig | 0.49 | 7.5 | 0.01 | Jul 14, 2022 | Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function. | ||
| CVE-2022-26267 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2022 | Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php. | ||
| CVE-2014-8937 | Hig | 0.49 | 7.5 | 0.01 | Jun 1, 2020 | Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources. | ||
| CVE-2017-10679 | Hig | 0.49 | 7.5 | 0.02 | Jun 29, 2017 | Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed. | ||
| CVE-2016-3735 | Hig | 0.46 | 8.1 | 0.01 | Jan 28, 2022 | Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed used to generate it. This low an unauthenticated attacker… | ||
| CVE-2014-4613 | Med | 0.46 | 6.5 | 0.03 | Mar 16, 2018 | Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php. | ||
| CVE-2026-27833 | Hig | 0.42 | 7.5 | 0.02 | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This… | ||
| CVE-2024-43018 | Med | 0.42 | 6.4 | 0.00 | Jul 29, 2025 | Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for… | ||
| CVE-2017-16893 | Med | 0.42 | 6.5 | 0.01 | Dec 1, 2017 | The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database.… | ||
| CVE-2017-9463 | Med | 0.42 | 6.5 | 0.02 | Jun 14, 2017 | The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The… | ||
| CVE-2026-27885 | Hig | 0.40 | 7.2 | 0.00 | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the… | ||
| CVE-2026-27834 | Hig | 0.40 | 7.2 | 0.00 | Apr 3, 2026 | Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing… | ||
| CVE-2024-46605 | Med | 0.40 | 6.1 | 0.00 | Oct 16, 2024 | A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | ||
| CVE-2023-51790 | Med | 0.40 | 6.1 | 0.01 | Jan 12, 2024 | Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component. | ||
| CVE-2022-37183 | Med | 0.40 | 6.1 | 0.01 | Aug 31, 2022 | Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list. | ||
| CVE-2021-45357 | Med | 0.40 | 6.1 | 0.01 | Feb 10, 2022 | Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.php. | ||
| CVE-2021-40882 | Med | 0.40 | 6.1 | 0.01 | Dec 14, 2021 | A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location. | ||
| CVE-2020-22150 | Med | 0.40 | 6.1 | 0.01 | Jul 21, 2021 | A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML. | ||
| CVE-2020-22148 | Med | 0.40 | 6.1 | 0.01 | Jul 21, 2021 | A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML. | ||
| CVE-2020-9467 | Med | 0.40 | 5.4 | 0.24 | Mar 26, 2020 | Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. |
- risk 0.67cvss 9.8epss 0.09
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
- risk 0.67cvss 9.8epss 0.08
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
- risk 0.65cvss 9.8epss 0.16
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
- risk 0.64cvss 9.8epss 0.01
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
- risk 0.64cvss 9.8epss 0.02
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
- risk 0.64cvss 9.8epss 0.01
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.
- risk 0.64cvss 9.8epss 0.03
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
- risk 0.63cvss 9.6epss 0.01
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
- risk 0.63cvss 9.6epss 0.01
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_detailed_content, nbm_complementary_mail_content, nbm_send_recent_post_dates, or param_submit…
- risk 0.61cvss 8.8epss 0.10
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
- risk 0.57cvss 9.8epss 0.01
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without…
- risk 0.57cvss 8.8epss 0.00
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
- risk 0.57cvss 8.8epss 0.01
Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php.
- risk 0.57cvss 8.8epss 0.02
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
- risk 0.57cvss 8.8epss 0.01
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
- risk 0.57cvss 8.8epss 0.01
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
- risk 0.57cvss 8.8epss 0.01
Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.
- risk 0.57cvss 8.8epss 0.01
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.
- risk 0.57cvss 8.8epss 0.01
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
- risk 0.57cvss 8.8epss 0.00
Lexiglot through 2014-11-20 allows CSRF.
- risk 0.57cvss 8.8epss 0.01
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions.
- risk 0.57cvss 8.8epss 0.01
admin/configuration.php in Piwigo 2.9.2 has CSRF.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.
- risk 0.57cvss 9.8epss 0.02
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosure and code execution if it contains a .. sequence.
- risk 0.51cvss 7.2epss 0.11
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
- risk 0.51cvss 7.8epss 0.00
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.
- risk 0.49cvss 7.5epss 0.01
Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.
- risk 0.49cvss 7.5epss 0.01
Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.
- risk 0.49cvss 7.5epss 0.01
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.
- risk 0.49cvss 7.5epss 0.02
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed.
- risk 0.46cvss 8.1epss 0.01
Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed used to generate it. This low an unauthenticated attacker…
- risk 0.46cvss 6.5epss 0.03
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.
- risk 0.42cvss 7.5epss 0.02
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This…
- risk 0.42cvss 6.4epss 0.00
Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at some point can be used for…
- risk 0.42cvss 6.5epss 0.01
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database.…
- risk 0.42cvss 6.5epss 0.02
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The…
- risk 0.40cvss 7.2epss 0.00
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the…
- risk 0.40cvss 7.2epss 0.00
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing…
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.
- risk 0.40cvss 6.1epss 0.01
Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Piwigo 12.x via the pwg_activity function in include/functions.inc.php.
- risk 0.40cvss 6.1epss 0.01
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.
- risk 0.40cvss 6.1epss 0.01
A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
- risk 0.40cvss 6.1epss 0.01
A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
- risk 0.40cvss 5.4epss 0.24
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Page 1 of 3