Piwigo records
114 published records for vendor piwigo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 0.9%
- Pre-auth RCE
- 9
- With a fix record
- 5.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')42
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')36
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-284 Improper Access Control3
The weakness classes this vendor ships most often: where to look.
CWEAll records
114 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2020-19213No exploit | SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.piwigo · piwigo · CWE-89 | Critical9.8 | — | 15.9% | May 6, 2022 |
42Plan | CVE-2023-33362Proof of concept | Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.piwigo · piwigo · CWE-89 | Critical9.8 | — | 9.1% | May 23, 2023 |
41Plan | CVE-2017-10682Proof of concept | SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via piwigo · piwigo · CWE-89 | Critical9.8 | — | 8.3% | Jun 29, 2017 |
40Plan | CVE-2014-8945No exploit | admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.piwigo · lexiglot · CWE-78 | Critical9.8 | — | 2.4% | Jun 1, 2020 |
40Plan | CVE-2016-10105No exploit | admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files.piwigo · piwigo · CWE-200 | Critical9.8 | — | 2.4% | Jan 3, 2017 |
40Plan | CVE-2021-32615No exploit | Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.piwigo · piwigo · CWE-89 | Critical9.8 | — | 2.1% | May 13, 2021 |
40Plan | CVE-2014-4648No exploit | Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."piwigo · piwigo | Critical10.0 | — | 1.5% | Jun 28, 2014 |
39Monitor | CVE-2014-8941No exploit | Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.piwigo · lexiglot · CWE-89 | Critical9.8 | — | 1.1% | Jun 1, 2020 |
39Monitor | CVE-2023-33361No exploit | Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.piwigo · piwigo · CWE-89 | Critical9.8 | — | 0.9% | May 23, 2023 |
39Monitor | CVE-2014-125053No exploit | Piwigo-Guest-Book Navigation Bar guestbook.inc.php sql injectionpiwigo · guestbook · CWE-89 | Critical9.8 | — | 0.7% | Jan 6, 2023 |
38Monitor | CVE-2023-26876Weaponized | SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id papiwigo · piwigo · CWE-89 | High8.8 | — | 9.7% | Apr 21, 2023 |
38Monitor | CVE-2019-13363No exploit | admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_sepiwigo · piwigo · CWE-79 | Critical9.6 | — | 1.4% | Sep 13, 2019 |
38Monitor | CVE-2019-13364No exploit | admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter.piwigo · piwigo · CWE-79 | Critical9.6 | — | 1.4% | Sep 13, 2019 |
36Monitor | CVE-2023-37270Proof of concept | Piwigo SQL Injection vulnerability in "User-Agent"piwigo · piwigo · CWE-89 | High8.8 | — | 4.5% | Jul 7, 2023 |
36Monitor | CVE-2021-40553No exploit | piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.piwigo · piwigo · CWE-94 | High8.8 | — | 2.3% | Jun 28, 2022 |
35Monitor | CVE-2022-26266No exploit | Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.piwigo · piwigo · CWE-89 | High8.8 | — | 1.3% | Mar 18, 2022 |
35Monitor | CVE-2017-10678No exploit | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for repiwigo · piwigo · CWE-352 | High8.8 | — | 1.2% | Jun 29, 2017 |
35Monitor | CVE-2017-10680No exploit | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for repiwigo · piwigo · CWE-352 | High8.8 | — | 1.2% | Jun 29, 2017 |
35Monitor | CVE-2017-10681No exploit | Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for repiwigo · piwigo · CWE-352 | High8.8 | — | 1.2% | Jun 29, 2017 |
35Monitor | CVE-2021-40313No exploit | Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.piwigo · piwigo · CWE-89 | High8.8 | — | 1.1% | Dec 6, 2021 |
35Monitor | CVE-2020-19215No exploit | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.piwigo · piwigo · CWE-89 | High8.8 | — | 1.0% | May 6, 2022 |
35Monitor | CVE-2020-19216No exploit | SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.piwigo · piwigo · CWE-89 | High8.8 | — | 1.0% | May 6, 2022 |
35Monitor | CVE-2020-19217No exploit | SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.piwigo · piwigo · CWE-89 | High8.8 | — | 1.0% | May 6, 2022 |
35Monitor | CVE-2014-8943No exploit | Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.piwigo · lexiglot · CWE-918 | High8.8 | — | 1.0% | Jun 1, 2020 |
35Monitor | CVE-2021-40317No exploit | Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.piwigo · piwigo · CWE-89 | High8.8 | — | 1.0% | May 26, 2022 |
- CVE-2020-1921344Plan
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.
CriticalCVSS 9.8No exploitEPSS 16%piwigo · piwigoMay 6, 2022
- CVE-2023-3336242Plan
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
CriticalCVSS 9.8Proof of conceptEPSS 9%piwigo · piwigoMay 23, 2023
- CVE-2017-1068241Plan
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via
CriticalCVSS 9.8Proof of conceptEPSS 8%piwigo · piwigoJun 29, 2017
- CVE-2014-894540Plan
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
CriticalCVSS 9.8No exploitEPSS 2%piwigo · lexiglotJun 1, 2020
- CVE-2016-1010540Plan
admin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files.
CriticalCVSS 9.8No exploitEPSS 2%piwigo · piwigoJan 3, 2017
- CVE-2021-3261540Plan
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.
CriticalCVSS 9.8No exploitEPSS 2%piwigo · piwigoMay 13, 2021
- CVE-2014-464840Plan
Unspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."
CriticalCVSS 10.0No exploitEPSS 1%piwigo · piwigoJun 28, 2014
- CVE-2014-894139Monitor
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.
CriticalCVSS 9.8No exploitEPSS 1%piwigo · lexiglotJun 1, 2020
- CVE-2023-3336139Monitor
Piwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.
CriticalCVSS 9.8No exploitEPSS 1%piwigo · piwigoMay 23, 2023
- CVE-2014-12505339Monitor
Piwigo-Guest-Book Navigation Bar guestbook.inc.php sql injection
CriticalCVSS 9.8No exploitEPSS 1%piwigo · guestbookJan 6, 2023
- CVE-2023-2687638Monitor
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id pa
HighCVSS 8.8WeaponizedEPSS 10%piwigo · piwigoApr 21, 2023
- CVE-2019-1336338Monitor
admin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_se
CriticalCVSS 9.6No exploitEPSS 1%piwigo · piwigoSep 13, 2019
- CVE-2019-1336438Monitor
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter.
CriticalCVSS 9.6No exploitEPSS 1%piwigo · piwigoSep 13, 2019
- CVE-2023-3727036Monitor
Piwigo SQL Injection vulnerability in "User-Agent"
HighCVSS 8.8Proof of conceptEPSS 5%piwigo · piwigoJul 7, 2023
- CVE-2021-4055336Monitor
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
HighCVSS 8.8No exploitEPSS 2%piwigo · piwigoJun 28, 2022
- CVE-2022-2626635Monitor
Piwigo v12.2.0 was discovered to contain a SQL injection vulnerability via pwg.users.php.
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoMar 18, 2022
- CVE-2017-1067835Monitor
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for re
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoJun 29, 2017
- CVE-2017-1068035Monitor
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for re
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoJun 29, 2017
- CVE-2017-1068135Monitor
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for re
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoJun 29, 2017
- CVE-2021-4031335Monitor
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoDec 6, 2021
- CVE-2020-1921535Monitor
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoMay 6, 2022
- CVE-2020-1921635Monitor
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoMay 6, 2022
- CVE-2020-1921735Monitor
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoMay 6, 2022
- CVE-2014-894335Monitor
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
HighCVSS 8.8No exploitEPSS 1%piwigo · lexiglotJun 1, 2020
- CVE-2021-4031735Monitor
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
HighCVSS 8.8No exploitEPSS 1%piwigo · piwigoMay 26, 2022