Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-27834 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getLis… Piwigo 16.3.0+ Fix from $1,9502026-04-03 HIGH 7.2 CVE-2026-27885 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affec… Piwigo 16.3.0+ Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-27634 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max… Piwigo 16.3.0+ Fix from $2,3002026-04-03 HIGH 7.5 CVE-2026-27833 Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered wi… Piwigo 16.3.0+ Fix from $1,9502026-04-03 MEDIUM 5.3 CVE-2025-62512 Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality … Piwigo after 15.5.0 Fix from $1,6002026-02-24 HIGH 7.5 CVE-2024-48928 Piwigo is an open source photo gallery application for the web. In versions on the 14.x branch, when installing, the secret_key configuration paramet… Piwigo after 14.5.0 Fix from $1,9502026-02-24 HIGH 8.8 CVE-2025-62406 Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a pas… Piwigo Patch available Fix from $1,9502025-11-18 MEDIUM 6.4 CVE-2024-43018 Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList fun… Piwigo after 13.8.0 Fix from $1,6002025-07-29 MEDIUM 5.4 CVE-2024-52701 A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HT… Piwigo No fix yet Fix from $1,6002024-11-20 HIGH 8.8 CVE-2024-48311 Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. Piwigo No fix yet Fix from $1,9502024-10-31 MEDIUM 6.1 CVE-2024-46605 A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts… Piwigo after 14.5.0 Fix from $1,6002024-10-16 MEDIUM 5.4 CVE-2024-46606 A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts… Piwigo after 14.5.0 Fix from $1,6002024-10-16 MEDIUM 5.4 CVE-2024-28662 A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.p… Piwigo Patch available Fix from $1,6002024-03-13 MEDIUM 5.4 CVE-2024-26450 An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Req… Piwigo Mitigation only Fix from $1,6002024-02-28 MEDIUM 6.1 CVE-2023-51790 Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin To… Piwigo No fix yet Fix from $1,6002024-01-12 MEDIUM 6.1 CVE-2023-44393 Piwigo is an open source photo gallery application. Prior to version 14.0.0beta4, a reflected cross-site scripting (XSS) vulnerability is in the` /ad… Piwigo after 13.8.0 Fix from $1,6002023-10-09 HIGH 8.8 CVE-2023-37270 Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator scree… Piwigo 13.8.0+ Fix from $1,9502023-07-07 CRITICAL 9.8 CVE-2023-33361 Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php. Piwigo Patch available Fix from $2,3002023-05-23 CRITICAL 9.8 CVE-2023-33362EPSS 9% Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. Piwigo Patch available Fix from $2,3002023-05-23 HIGH 8.8 CVE-2023-27233 Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at user_list_backend.php. Piwigo 13.6.0+ Fix from $1,9502023-05-17 HIGH 8.8 CVE-2023-26876EPSS 10% SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter t… Piwigo after 13.5.0 Fix from $1,9502023-04-21 MEDIUM 5.4 CVE-2022-48007 A stored cross-site scripting (XSS) vulnerability in identification.php of Piwigo v13.4.0 allows attackers to execute arbitrary web scripts or HTML v… Piwigo Patch available Fix from $1,6002023-01-27 CRITICAL 9.8 CVE-2014-125053 A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file inc… Guestbook 1.3.1+ Fix from $2,3002023-01-06 MEDIUM 6.1 CVE-2022-37183 Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list. Piwigo No fix yet Fix from $1,6002022-08-31 HIGH 7.5 CVE-2022-32297 Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function. Piwigo after 12.2.0 Fix from $1,9502022-07-14 HIGH 8.8 CVE-2021-40553 piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor. Piwigo No fix yet Fix from $1,9502022-06-28 MEDIUM 5.4 CVE-2021-40678 In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit. Piwigo No fix yet Fix from $1,6002022-06-14 HIGH 8.8 CVE-2021-40317 Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter. Piwigo No fix yet Fix from $1,9502022-05-26 CRITICAL 9.8 CVE-2020-19213EPSS 16% SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories. Piwigo No fix yet Fix from $2,3002022-05-06 HIGH 8.8 CVE-2020-19215 SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm. Piwigo No fix yet Fix from $1,9502022-05-06