Piwigo

Piwigo

104 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.32%
  • Veröffentlicht 20.07.2026 16:27:09
  • Zuletzt bearbeitet 21.07.2026 20:27:18

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 03.04.2026 21:36:07
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extr...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 03.04.2026 21:35:13
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without prop...

Exploit
  • EPSS 1.64%
  • Veröffentlicht 03.04.2026 21:34:11
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of al...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 03.04.2026 21:33:13
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenate...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 24.02.2026 16:43:28
  • Zuletzt bearbeitet 25.02.2026 16:53:02

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address e...

  • EPSS 0.26%
  • Veröffentlicht 24.02.2026 16:39:56
  • Zuletzt bearbeitet 25.02.2026 16:53:44

Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration parameter is set to MD5(RAND()) in MySQL. However, RAND() only has 30 bits of randomness, making it feasible...

Exploit
  • EPSS 0.4%
  • Veröffentlicht 18.11.2025 22:18:45
  • Zuletzt bearbeitet 25.11.2025 18:39:37

Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset URL by entering an existing username or email address. However, the hostname used to cons...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 29.07.2025 00:00:00
  • Zuletzt bearbeitet 06.08.2025 16:24:27

Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.php and this same function is called by ws.php file at...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 20.11.2024 21:15:08
  • Zuletzt bearbeitet 22.05.2025 17:28:18

A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter.