Vulnerability index

Browse CVEs

95 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2018-7722 The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-1… Piwigo No fix yet Fix from $1,6002018-03-06 MEDIUM 5.4 CVE-2018-7723 The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-… Piwigo No fix yet Fix from $1,6002018-03-06 MEDIUM 5.4 CVE-2018-7724 The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel… Piwigo No fix yet Fix from $1,6002018-03-06 MEDIUM 6.1 CVE-2018-5692 Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file. Piwigo No fix yet Fix from $1,6002018-01-14 HIGH 8.8 CVE-2017-17827 Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration&section=main or /admin.php?page=batch_manager&mode=unit. A… Piwigo Patch available Fix from $1,9502017-12-21 MEDIUM 6.1 CVE-2017-17826 The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=con… Piwigo No fix yet Fix from $1,6002017-12-21 HIGH 8.8 CVE-2017-17774 admin/configuration.php in Piwigo 2.9.2 has CSRF. Piwigo Patch available Fix from $1,9502017-12-20 MEDIUM 6.1 CVE-2017-17775 Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request. Piwigo No fix yet Fix from $1,6002017-12-20 MEDIUM 6.5 CVE-2017-16893 The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authentica… Piwigo after 2.9.2 Fix from $1,6002017-12-01 MEDIUM 6.5 CVE-2016-10514 url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that co… Piwigo after 2.8.2 Fix from $1,6002017-10-10 MEDIUM 6.1 CVE-2016-10513 Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php. Piwigo after 2.8.2 Fix from $1,6002017-10-10 CRITICAL 9.8 CVE-2017-10682EPSS 8% SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_f… Piwigo after 2.9.1 Fix from $2,3002017-06-29 HIGH 8.8 CVE-2017-10678 Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to… Piwigo after 2.9.1 Fix from $1,9502017-06-29 HIGH 8.8 CVE-2017-10680 Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to… Piwigo after 2.9.1 Fix from $1,9502017-06-29 HIGH 8.8 CVE-2017-10681 Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to… Piwigo after 2.9.1 Fix from $1,9502017-06-29 HIGH 7.5 CVE-2017-10679 Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL … Piwigo after 2.9.1 Fix from $1,9502017-06-29 MEDIUM 6.5 CVE-2017-9463 The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticat… Piwigo after 2.9.0 Fix from $1,6002017-06-14 MEDIUM 6.1 CVE-2017-9464 An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sit… Piwigo after 2.9.0 Fix from $1,6002017-06-14 MEDIUM 6.1 CVE-2017-5608 Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script o… Piwigo after 2.8.5 Fix from $1,6002017-01-28 CRITICAL 9.8 CVE-2016-10105 admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosur… Piwigo after 2.8.3 Fix from $2,3002017-01-03 HIGH 7.2 CVE-2016-10084 admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] var… Piwigo after 2.8.3 Fix from $1,9502016-12-30 HIGH 7.2 CVE-2016-10085 admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter. Piwigo after 2.8.3 Fix from $1,9502016-12-30 MEDIUM 6.1 CVE-2016-10083 Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML v… Piwigo after 2.8.3 Fix from $1,6002016-12-30 MEDIUM 6.1 CVE-2016-9751 Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HT… Piwigo Patch available Fix from $1,6002016-12-01 MEDIUM 6.5 CVE-2015-2035 SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via t… Piwigo after 2.7.3 Fix from $1,6002015-02-20 MEDIUM 6.0 CVE-2015-1517 SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL comman… Piwigo after 2.7.3 Fix from $1,6002015-02-20 HIGH 7.5 CVE-2015-1441 SQL injection vulnerability in Piwigo before 2.5.6, 2.6.x before 2.6.5, and 2.7.x before 2.7.3 allows remote attackers to execute arbitrary SQL comma… Piwigo after 2.5.5 Fix from $1,9502015-02-03 HIGH 7.5 CVE-2014-9115 SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x befo… Piwigo after 2.5.5 Fix from $1,9502014-12-23 MEDIUM 6.8 CVE-2014-4614 Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrato… Piwigo after 2.6.1 Fix from $1,6002014-07-02 HIGH 10.0 CVE-2014-4648 Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure." Piwigo after 2.6.2 Fix from $1,9502014-06-28