Skip to content
Noroxi

Piwigo records

114 published records for vendor piwigo.

All records

114 records
  • SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

    CriticalCVSS 9.8No exploitEPSS 16%

    piwigo · piwigoMay 6, 2022

  • Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.

    CriticalCVSS 9.8Proof of conceptEPSS 9%

    piwigo · piwigoMay 23, 2023

  • SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    piwigo · piwigoJun 29, 2017

  • admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.

    CriticalCVSS 9.8No exploitEPSS 2%

    piwigo · lexiglotJun 1, 2020

  • admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files.

    CriticalCVSS 9.8No exploitEPSS 2%

    piwigo · piwigoJan 3, 2017

  • Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.

    CriticalCVSS 9.8No exploitEPSS 2%

    piwigo · piwigoMay 13, 2021

  • Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."

    CriticalCVSS 10.0No exploitEPSS 1%

    piwigo · piwigoJun 28, 2014

  • CVE-2014-8941
    39Monitor

    Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.

    CriticalCVSS 9.8No exploitEPSS 1%

    piwigo · lexiglotJun 1, 2020

  • Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.

    CriticalCVSS 9.8No exploitEPSS 1%

    piwigo · piwigoMay 23, 2023

  • Piwigo-Guest-Book Navigation Bar guestbook.inc.php sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    piwigo · guestbookJan 6, 2023

  • SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id pa

    HighCVSS 8.8WeaponizedEPSS 10%

    piwigo · piwigoApr 21, 2023

  • admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_se

    CriticalCVSS 9.6No exploitEPSS 1%

    piwigo · piwigoSep 13, 2019

  • admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter.

    CriticalCVSS 9.6No exploitEPSS 1%

    piwigo · piwigoSep 13, 2019

  • Piwigo SQL Injection vulnerability in "User-Agent"

    HighCVSS 8.8Proof of conceptEPSS 5%

    piwigo · piwigoJul 7, 2023

  • piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.

    HighCVSS 8.8No exploitEPSS 2%

    piwigo · piwigoJun 28, 2022

  • Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoMar 18, 2022

  • Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for re

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoJun 29, 2017

  • Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for re

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoJun 29, 2017

  • Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for re

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoJun 29, 2017

  • Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoDec 6, 2021

  • SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoMay 6, 2022

  • SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoMay 6, 2022

  • SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoMay 6, 2022

  • CVE-2014-8943
    35Monitor

    Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · lexiglotJun 1, 2020

  • Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.

    HighCVSS 8.8No exploitEPSS 1%

    piwigo · piwigoMay 26, 2022