Filtered by vendor Piwigo
Subscriptions
Total
106 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-46333 | 1 Piwigo | 1 Piwigo | 2025-05-27 | 4.8 Medium |
An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Album Name parameter under the Add Album function. | ||||
CVE-2024-28662 | 1 Piwigo | 1 Piwigo | 2025-05-23 | 5.4 Medium |
A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php. | ||||
CVE-2024-52701 | 1 Piwigo | 1 Piwigo | 2025-05-22 | 5.4 Medium |
A stored cross-site scripting (XSS) vulnerability in the Configuration page of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page banner parameter. | ||||
CVE-2024-48311 | 1 Piwigo | 1 Piwigo | 2025-05-22 | 8.8 High |
Piwigo v14.5.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Edit album function. | ||||
CVE-2024-46606 | 1 Piwigo | 1 Piwigo | 2025-05-22 | 5.4 Medium |
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=photo of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | ||||
CVE-2024-46605 | 1 Piwigo | 1 Piwigo | 2025-05-22 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability in the component /admin.php?page=album of Piwigo v14.5.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Description field. | ||||
CVE-2024-26450 | 1 Piwigo | 1 Piwigo | 2025-05-13 | 5.4 Medium |
An issue exists within Piwigo before v.14.2.0 allowing a malicious user to take over the application. This exploit involves chaining a Cross Site Request Forgery vulnerability to issue a Stored Cross Site Scripting payload stored within an Admin user's dashboard, executing remote JavaScript. This can be used to upload a new PHP file under an administrator and directly call that file from the victim's instance to connect back to a malicious listener. | ||||
CVE-2017-17827 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Piwigo 2.9.2 is vulnerable to Cross-Site Request Forgery via /admin.php?page=configuration§ion=main or /admin.php?page=batch_manager&mode=unit. An attacker can exploit this to coerce an admin user into performing unintended actions. | ||||
CVE-2017-17825 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
The Batch Manager component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via tags-* array parameters in an admin.php?page=batch_manager&mode=unit request. An attacker can exploit this to hijack a client's browser along with the data stored in it. | ||||
CVE-2017-5608 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename. | ||||
CVE-2017-17774 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
admin/configuration.php in Piwigo 2.9.2 has CSRF. | ||||
CVE-2017-17824 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
The Batch Manager component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/batch_manager_unit.php element_ids parameter in unit mode. An attacker can exploit this to gain access to the data in a connected MySQL database. | ||||
CVE-2017-17775 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request. | ||||
CVE-2017-17826 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
The Configuration component of Piwigo 2.9.2 is vulnerable to Persistent Cross Site Scripting via the gallery_title parameter in an admin.php?page=configuration§ion=main request. An attacker can exploit this to hijack a client's browser along with the data stored in it. | ||||
CVE-2017-10681 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request. | ||||
CVE-2017-10680 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request. | ||||
CVE-2017-10682 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php. | ||||
CVE-2016-10513 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php. | ||||
CVE-2017-10679 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album. The permalink ID numbers are easily guessed. | ||||
CVE-2017-17823 | 1 Piwigo | 1 Piwigo | 2025-04-20 | N/A |
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter. An attacker can exploit this to gain access to the data in a connected MySQL database. |