Piwigo

Piwigo

112 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 25.09.2026 15:50:34
  • Zuletzt bearbeitet 28.09.2026 15:17:17

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo when constructin...

  • EPSS 0.92%
  • Veröffentlicht 25.09.2026 15:48:55
  • Zuletzt bearbeitet 25.09.2026 17:17:08

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The stored album image...

  • EPSS 1.29%
  • Veröffentlicht 25.09.2026 15:47:59
  • Zuletzt bearbeitet 25.09.2026 17:17:08

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc...

  • EPSS 0.3%
  • Veröffentlicht 25.09.2026 15:46:04
  • Zuletzt bearbeitet 29.09.2026 20:17:21

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the retur...

  • EPSS 0.37%
  • Veröffentlicht 25.09.2026 15:42:01
  • Zuletzt bearbeitet 28.09.2026 15:17:17

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager filter URL wit...

  • EPSS 1.21%
  • Veröffentlicht 25.09.2026 13:51:07
  • Zuletzt bearbeitet 25.09.2026 15:17:56

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing format confusio...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 02.09.2026 02:15:08
  • Zuletzt bearbeitet 04.09.2026 03:17:44

A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the ...

  • EPSS 0.41%
  • Veröffentlicht 24.08.2026 05:16:55
  • Zuletzt bearbeitet 24.08.2026 17:18:18

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high compl...

  • EPSS 0.32%
  • Veröffentlicht 20.07.2026 16:27:09
  • Zuletzt bearbeitet 21.07.2026 20:27:18

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 03.04.2026 21:36:07
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extr...