Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Piwigo MEDIUM 5.4
CVE-2018-7722

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-1…

No fix yet
Fix from $1,600 2018-03-06
Piwigo MEDIUM 5.4
CVE-2018-7723

The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-…

No fix yet
Fix from $1,600 2018-03-06
Piwigo MEDIUM 5.4
CVE-2018-7724

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel…

No fix yet
Fix from $1,600 2018-03-06
Piwigo MEDIUM 6.1
CVE-2018-5692

Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.

No fix yet
Fix from $1,600 2018-01-14
Piwigo HIGH 8.8
CVE-2017-17827

Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. A…

Patch available
Fix from $1,950 2017-12-21
Piwigo MEDIUM 6.1
CVE-2017-17826

The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=con…

No fix yet
Fix from $1,600 2017-12-21
Piwigo HIGH 8.8
CVE-2017-17774

admin/configuration.php in Piwigo 2.9.2 has CSRF.

Patch available
Fix from $1,950 2017-12-20
Piwigo MEDIUM 6.1
CVE-2017-17775

Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.

No fix yet
Fix from $1,600 2017-12-20
Piwigo MEDIUM 6.5
CVE-2017-16893

The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authentica…

Fix: after 2.9.2
Fix from $1,600 2017-12-01
Piwigo MEDIUM 6.5
CVE-2016-10514

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that co…

Fix: after 2.8.2
Fix from $1,600 2017-10-10
Piwigo MEDIUM 6.1
CVE-2016-10513

Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.

Fix: after 2.8.2
Fix from $1,600 2017-10-10
Piwigo CRITICAL 9.8
CVE-2017-10682EPSS 8%

SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_f…

Fix: after 2.9.1
Fix from $2,300 2017-06-29
Piwigo HIGH 8.8
CVE-2017-10678

Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Piwigo HIGH 8.8
CVE-2017-10680

Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Piwigo HIGH 8.8
CVE-2017-10681

Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Piwigo HIGH 7.5
CVE-2017-10679

Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL …

Fix: after 2.9.1
Fix from $1,950 2017-06-29
Piwigo MEDIUM 6.5
CVE-2017-9463

The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticat…

Fix: after 2.9.0
Fix from $1,600 2017-06-14
Piwigo MEDIUM 6.1
CVE-2017-9464

An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sit…

Fix: after 2.9.0
Fix from $1,600 2017-06-14
Piwigo MEDIUM 6.1
CVE-2017-5608

Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script o…

Fix: after 2.8.5
Fix from $1,600 2017-01-28
Piwigo CRITICAL 9.8
CVE-2016-10105

admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosur…

Fix: after 2.8.3
Fix from $2,300 2017-01-03
Piwigo HIGH 7.2
CVE-2016-10084

admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] var…

Fix: after 2.8.3
Fix from $1,950 2016-12-30
Piwigo HIGH 7.2
CVE-2016-10085

admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.

Fix: after 2.8.3
Fix from $1,950 2016-12-30
Piwigo MEDIUM 6.1
CVE-2016-10083

Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML v…

Fix: after 2.8.3
Fix from $1,600 2016-12-30
Piwigo MEDIUM 6.1
CVE-2016-9751

Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HT…

Patch available
Fix from $1,600 2016-12-01
Piwigo MEDIUM 6.5
CVE-2015-2035

SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via t…

Fix: after 2.7.3
Fix from $1,600 2015-02-20
Piwigo MEDIUM 6.0
CVE-2015-1517

SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL comman…

Fix: after 2.7.3
Fix from $1,600 2015-02-20
Piwigo HIGH 7.5
CVE-2015-1441

SQL injection vulnerability in Piwigo before 2.5.6, 2.6.x before 2.6.5, and 2.7.x before 2.7.3 allows remote attackers to execute arbitrary SQL comma…

Fix: after 2.5.5
Fix from $1,950 2015-02-03
Piwigo HIGH 7.5
CVE-2014-9115

SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x befo…

Fix: after 2.5.5
Fix from $1,950 2014-12-23
Piwigo MEDIUM 6.8
CVE-2014-4614

Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrato…

Fix: after 2.6.1
Fix from $1,600 2014-07-02
Piwigo HIGH 10.0
CVE-2014-4648

Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."

Fix: after 2.6.2
Fix from $1,950 2014-06-28