Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
piwigo vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2009-2933
SQL injection vulnerability in comments.php in Piwigo prior to 2.0.3 allows remote malicious users to execute arbitrary SQL commands via the items_number parameter.
Piwigo Piwigo
NA
CVE-2023-34626
Piwigo 13.7.0 is vulnerable to SQL Injection via the "Users" function.
Piwigo Piwigo
4
CVSSv2
CVE-2017-16893
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior. This vulnerability allows remote authenticated malicious users to obtain information in the context of the user used by the application to retrieve data from the database. ta...
Piwigo Piwigo
4.3
CVSSv2
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo prior to 2.6.2 allows remote malicious users to hijack the authentication of administrators for requests that add users via a pwg.users.add action in a request to ws.php.
Piwigo Piwigo
1 EDB exploit
5.1
CVSSv2
CVE-2022-32297
Piwigo v12.2.0 exists to contain SQL injection vulnerability via the Search function.
Piwigo Piwigo
6.5
CVSSv2
CVE-2021-40313
Piwigo v11.5 exists to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.
Piwigo Piwigo 11.5.0
4.3
CVSSv2
CVE-2021-40882
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.
Piwigo Piwigo 11.5.0
3.5
CVSSv2
CVE-2021-40678
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
Piwigo Piwigo 11.5.0
3.5
CVSSv2
CVE-2020-8089
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.
Piwigo Piwigo 2.10.1
4
CVSSv2
CVE-2020-9468
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.
Piwigo Piwigo 2.9.0
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-2907
hardcoded
inject
CVE-2024-20359
CVE-2024-2467
CVE-2024-4077
CVE-2024-22391
camera
CVE-2024-20353
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
10
NEXT »