Skip to main content

Vendor archive

piwigo CVEs

Beta · best-effort

114 CVEs tagged to vendor piwigo12 Critical, 38 High, 63 Medium, 1 Low, 0 Unrated.

CVE-2026-27885

Published Apr 3, 2026

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API end…

CVSS 7.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-27834

Published Apr 3, 2026

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The…

CVSS 7.2 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-27833

Published Apr 3, 2026

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, a…

CVSS 7.5 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2026-27634

Published Apr 3, 2026

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_cr…

CVSS 8.7 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2025-62512

Published Feb 24, 2026

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenti…

CVSS 5.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-48928

Published Feb 24, 2026

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in My…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-62406

Published Nov 18, 2025

Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset URL by entering an…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-43018

Published Jul 29, 2025

Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_fun…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52701

Published Nov 20, 2024

A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injec…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48311

Published Oct 31, 2024

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46606

Published Oct 16, 2024

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46605

Published Oct 16, 2024

A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46333

Published Sep 27, 2024

An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-28662

Published Mar 13, 2024

A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26450

Published Feb 28, 2024

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-51790

Published Jan 12, 2024

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-44393

Published Oct 9, 2023

Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&i…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-37270

Published Jul 7, 2023

Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acqu…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34626

Published Jun 15, 2023

Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33362

Published May 23, 2023

Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33361

Published May 23, 2023

Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33359

Published May 23, 2023

Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27233

Published May 17, 2023

Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-26876

Published Apr 21, 2023

SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&f…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-48007

Published Jan 27, 2023

A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 114 CVEsPage 1 of 5