Vulnerability index

Browse CVEs

30 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Piwigo MEDIUM 5.4
CVE-2024-52701

A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HT…

No fix yet
Fix from $1,600 2024-11-20
Piwigo HIGH 8.8
CVE-2024-48311

Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function.

No fix yet
Fix from $1,950 2024-10-31
Piwigo MEDIUM 5.4
CVE-2024-26450

An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Req…

Mitigation only
Fix from $1,600 2024-02-28
Piwigo MEDIUM 6.1
CVE-2023-51790

Cross Site Scripting vulnerability in piwigo v.14.0.0 allows a remote attacker to obtain sensitive information via the lang parameter in the Admin To…

No fix yet
Fix from $1,600 2024-01-12
Piwigo MEDIUM 6.1
CVE-2022-37183

Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.

No fix yet
Fix from $1,600 2022-08-31
Piwigo HIGH 8.8
CVE-2021-40553

piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.

No fix yet
Fix from $1,950 2022-06-28
Piwigo MEDIUM 5.4
CVE-2021-40678

In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.

No fix yet
Fix from $1,600 2022-06-14
Piwigo HIGH 8.8
CVE-2021-40317

Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.

No fix yet
Fix from $1,950 2022-05-26
Piwigo CRITICAL 9.8
CVE-2020-19213EPSS 16%

SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

No fix yet
Fix from $2,300 2022-05-06
Piwigo HIGH 8.8
CVE-2020-19215

SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.

No fix yet
Fix from $1,950 2022-05-06
Piwigo HIGH 8.8
CVE-2020-19216

SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.

No fix yet
Fix from $1,950 2022-05-06
Piwigo HIGH 8.8
CVE-2020-19217

SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.

No fix yet
Fix from $1,950 2022-05-06
Piwigo HIGH 8.8
CVE-2022-26266

Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.

No fix yet
Fix from $1,950 2022-03-18
Piwigo HIGH 7.5
CVE-2022-26267

Piwigo v12.2.0 was discovered to contain an information leak via the action parameter in /admin/maintenance_actions.php.

No fix yet
Fix from $1,950 2022-03-18
Piwigo MEDIUM 5.4
CVE-2022-24620

Piwigo version 12.2.0 is vulnerable to stored cross-site scripting (XSS), which can lead to privilege escalation. In this way, admin can steal webmas…

No fix yet
Fix from $1,600 2022-02-24
Piwigo MEDIUM 6.1
CVE-2021-40882

A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.

No fix yet
Fix from $1,600 2021-12-14
Piwigo HIGH 8.8
CVE-2021-40313

Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.

No fix yet
Fix from $1,950 2021-12-06
Piwigo MEDIUM 6.1
CVE-2020-22148

A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.

No fix yet
Fix from $1,600 2021-07-21
Piwigo MEDIUM 6.1
CVE-2020-22150

A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.

No fix yet
Fix from $1,600 2021-07-21
Piwigo MEDIUM 5.4
CVE-2020-8089

Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.

No fix yet
Fix from $1,600 2020-02-10
Piwigo CRITICAL 9.6
CVE-2019-13363

admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_de…

No fix yet
Fix from $2,300 2019-09-13
Piwigo CRITICAL 9.6
CVE-2019-13364

admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is e…

No fix yet
Fix from $2,300 2019-09-13
Piwigo MEDIUM 5.4
CVE-2018-7722

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-1…

No fix yet
Fix from $1,600 2018-03-06
Piwigo MEDIUM 5.4
CVE-2018-7723

The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-…

No fix yet
Fix from $1,600 2018-03-06
Piwigo MEDIUM 5.4
CVE-2018-7724

The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, rel…

No fix yet
Fix from $1,600 2018-03-06
Piwigo MEDIUM 6.1
CVE-2018-5692

Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.

No fix yet
Fix from $1,600 2018-01-14
Piwigo MEDIUM 6.1
CVE-2017-17826

The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=con…

No fix yet
Fix from $1,600 2017-12-21
Piwigo MEDIUM 6.1
CVE-2017-17775

Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.

No fix yet
Fix from $1,600 2017-12-20
Piwigo MEDIUM 6.5
CVE-2014-4649

SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to exe…

Mitigation only
Fix from $1,600 2014-06-28
Piwigo MEDIUM 5.0
CVE-2011-3790

Piwigo 2.1.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an e…

Mitigation only
Fix from $1,600 2011-09-24