Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2018-7722
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-1…
Piwigo
No fix yet
MEDIUM 5.4
CVE-2018-7723
The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-…
Piwigo
No fix yet
MEDIUM 5.4
CVE-2018-7724
The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel…
Piwigo
No fix yet
MEDIUM 6.1
CVE-2018-5692
Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.
Piwigo
No fix yet
HIGH 8.8
CVE-2017-17827
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. A…
Piwigo
Patch available
MEDIUM 6.1
CVE-2017-17826
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=con…
Piwigo
No fix yet
HIGH 8.8
CVE-2017-17774
admin/configuration.php in Piwigo 2.9.2 has CSRF.
Piwigo
Patch available
MEDIUM 6.1
CVE-2017-17775
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
Piwigo
No fix yet
MEDIUM 6.5
CVE-2017-16893
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authentica…
Piwigo
after 2.9.2
MEDIUM 6.5
CVE-2016-10514
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that co…
Piwigo
after 2.8.2
MEDIUM 6.1
CVE-2016-10513
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
Piwigo
after 2.8.2
CRITICAL 9.8
CVE-2017-10682EPSS 8%
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_f…
Piwigo
after 2.9.1
HIGH 8.8
CVE-2017-10678
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…
Piwigo
after 2.9.1
HIGH 8.8
CVE-2017-10680
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…
Piwigo
after 2.9.1
HIGH 8.8
CVE-2017-10681
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to…
Piwigo
after 2.9.1
HIGH 7.5
CVE-2017-10679
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL …
Piwigo
after 2.9.1
MEDIUM 6.5
CVE-2017-9463
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticat…
Piwigo
after 2.9.0
MEDIUM 6.1
CVE-2017-9464
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sit…
Piwigo
after 2.9.0
MEDIUM 6.1
CVE-2017-5608
Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script o…
Piwigo
after 2.8.5
CRITICAL 9.8
CVE-2016-10105
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosur…
Piwigo
after 2.8.3
HIGH 7.2
CVE-2016-10084
admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page['tab'] var…
Piwigo
after 2.8.3
HIGH 7.2
CVE-2016-10085
admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.
Piwigo
after 2.8.3
MEDIUM 6.1
CVE-2016-10083
Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML v…
Piwigo
after 2.8.3
MEDIUM 6.1
CVE-2016-9751
Cross-site scripting (XSS) vulnerability in the search results front end in Piwigo 2.8.3 allows remote attackers to inject arbitrary web script or HT…
Piwigo
Patch available
MEDIUM 6.5
CVE-2015-2035
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via t…
Piwigo
after 2.7.3
MEDIUM 6.0
CVE-2015-1517
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to execute arbitrary SQL comman…
Piwigo
after 2.7.3
HIGH 7.5
CVE-2015-1441
SQL injection vulnerability in Piwigo before 2.5.6, 2.6.x before 2.6.5, and 2.7.x before 2.7.3 allows remote attackers to execute arbitrary SQL comma…
Piwigo
after 2.5.5
HIGH 7.5
CVE-2014-9115
SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x befo…
Piwigo
after 2.5.5
MEDIUM 6.8
CVE-2014-4614
Multiple cross-site request forgery (CSRF) vulnerabilities in Piwigo before 2.6.2 allow remote attackers to hijack the authentication of administrato…
Piwigo
after 2.6.1
HIGH 10.0
CVE-2014-4648
Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."
Piwigo
after 2.6.2