← Back

Piwigo

piwigo

114 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Piwigo
piwigo
Lexiglot
lexiglot
Guestbook
guestbook

CVEs (114)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Piwigo
1Piwigo
Nov 21, 2024
Jan 28, 2022
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed...Show more
Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed used to generate it. This low an unauthenticated attacker to take over an account providing they know an administrators email address in order to be able to request password reset.Show less
1Piwigo
1Piwigo
Jun 17, 2026
Dec 14, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.
1Piwigo
1Piwigo
Jun 17, 2026
Dec 6, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.
1Piwigo
1Piwigo
Jun 17, 2026
Jul 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
1Piwigo
1Piwigo
Jun 17, 2026
Jul 21, 2021
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.
1Piwigo
1Piwigo
Jun 17, 2026
May 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
1Piwigo
1Localfiles Editor
Jun 17, 2026
Apr 26, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
1Piwigo
1Piwigo
Jun 17, 2026
Apr 2, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config install_name, intro_message, or new_file_content parameter.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Lexiglot through 2014-11-20 allows CSRF.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
5.3 MEDIUM· v3
4.3 MEDIUM· v2
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warn...Show more
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configuration that produces warning messages.Show less
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.
1Piwigo
1Lexiglot
Nov 21, 2024
Jun 1, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.
1Piwigo
1Piwigo
Jun 17, 2026
Mar 26, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.
1Piwigo
1Piwigo
Jun 17, 2026
Mar 26, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
1Piwigo
1Piwigo
Jun 17, 2026
Feb 10, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.