CVE-2024-46605
- EPSS 0.12%
- Veröffentlicht 16.10.2024 17:15:17
- Zuletzt bearbeitet 22.05.2025 17:25:36
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
CVE-2024-46606
- EPSS 0.29%
- Veröffentlicht 16.10.2024 17:15:17
- Zuletzt bearbeitet 22.05.2025 17:25:47
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field.
CVE-2024-46333
- EPSS 0.21%
- Veröffentlicht 27.09.2024 15:15:15
- Zuletzt bearbeitet 27.05.2025 19:12:19
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function.
CVE-2024-28662
- EPSS 0.65%
- Veröffentlicht 13.03.2024 21:16:01
- Zuletzt bearbeitet 23.05.2025 14:43:43
A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.
CVE-2024-26450
- EPSS 0.46%
- Veröffentlicht 28.02.2024 22:15:26
- Zuletzt bearbeitet 13.05.2025 14:59:43
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user...
CVE-2023-51790
- EPSS 0.33%
- Veröffentlicht 12.01.2024 13:15:11
- Zuletzt bearbeitet 17.06.2025 14:15:27
Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin Tools plug-in component.
CVE-2023-44393
- EPSS 4.7%
- Veröffentlicht 09.10.2023 15:15:10
- Zuletzt bearbeitet 21.11.2024 08:25:48
Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /admin.php?page=plugins&tab=new&installstatus=ok&plugin_id=[here]` page. This vulnerability can be explo...
CVE-2023-37270
- EPSS 59.21%
- Veröffentlicht 07.07.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:21
Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acquires the HTTP Header `User-Agent` is vulnerable at the endpoint that re...
CVE-2023-34626
- EPSS 0.33%
- Veröffentlicht 15.06.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:07:27
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
CVE-2023-33359
- EPSS 0.18%
- Veröffentlicht 23.05.2023 14:15:09
- Zuletzt bearbeitet 31.01.2025 18:15:33
Piwigo 13.6.0 is vulnerable to Cross Site Request Forgery (CSRF) in the "add tags" function.