Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.2
CVE-2026-27834
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getLis…
Piwigo
16.3.0+
HIGH 7.2
CVE-2026-27885
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affec…
Piwigo
16.3.0+
CRITICAL 9.8
CVE-2026-27634
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max…
Piwigo
16.3.0+
HIGH 7.5
CVE-2026-27833
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered wi…
Piwigo
16.3.0+
MEDIUM 5.3
CVE-2025-62512
Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality …
Piwigo
after 15.5.0
HIGH 7.5
CVE-2024-48928
Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration paramet…
Piwigo
after 14.5.0
HIGH 8.8
CVE-2025-62406
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a pas…
Piwigo
Patch available
MEDIUM 6.4
CVE-2024-43018
Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList fun…
Piwigo
after 13.8.0
MEDIUM 5.4
CVE-2024-52701
A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HT…
Piwigo
No fix yet
HIGH 8.8
CVE-2024-48311
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.
Piwigo
No fix yet
MEDIUM 6.1
CVE-2024-46605
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts…
Piwigo
after 14.5.0
MEDIUM 5.4
CVE-2024-46606
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts…
Piwigo
after 14.5.0
MEDIUM 5.4
CVE-2024-28662
A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.p…
Piwigo
Patch available
MEDIUM 5.4
CVE-2024-26450
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Req…
Piwigo
Mitigation only
MEDIUM 6.1
CVE-2023-51790
Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin To…
Piwigo
No fix yet
MEDIUM 6.1
CVE-2023-44393
Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /ad…
Piwigo
after 13.8.0
HIGH 8.8
CVE-2023-37270
Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator scree…
Piwigo
13.8.0+
CRITICAL 9.8
CVE-2023-33361
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
Piwigo
Patch available
CRITICAL 9.8
CVE-2023-33362EPSS 9%
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
Piwigo
Patch available
HIGH 8.8
CVE-2023-27233
Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php.
Piwigo
13.6.0+
HIGH 8.8
CVE-2023-26876EPSS 10%
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter t…
Piwigo
after 13.5.0
MEDIUM 5.4
CVE-2022-48007
A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML v…
Piwigo
Patch available
CRITICAL 9.8
CVE-2014-125053
A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file inc…
Guestbook
1.3.1+
MEDIUM 6.1
CVE-2022-37183
Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
Piwigo
No fix yet
HIGH 7.5
CVE-2022-32297
Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.
Piwigo
after 12.2.0
HIGH 8.8
CVE-2021-40553
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
Piwigo
No fix yet
MEDIUM 5.4
CVE-2021-40678
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
Piwigo
No fix yet
HIGH 8.8
CVE-2021-40317
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
Piwigo
No fix yet
CRITICAL 9.8
CVE-2020-19213EPSS 16%
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
Piwigo
No fix yet
HIGH 8.8
CVE-2020-19215
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
Piwigo
No fix yet