📦 Piwigo

by Piwigo

🔍 What is Piwigo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-44393

CRITICAL CVSS 9.3 Oct 9, 2023

A reflected XSS vulnerability in Piwigo's admin interface allows attackers to inject malicious JavaScript via crafted URLs. Only authenticated administrators are affected when they visit malicious lin...

CVE-2023-33361

CRITICAL CVSS 9.8 May 23, 2023

Piwigo 13.6.0 contains a SQL injection vulnerability in the /admin/permalinks.php endpoint that allows attackers to execute arbitrary SQL commands. This affects all Piwigo installations running versio...

CVE-2020-19213

CRITICAL CVSS 9.8 May 6, 2022

This is a critical SQL injection vulnerability in Piwigo's cat_move.php file that allows attackers to execute arbitrary SQL commands via the 'selection' parameter when moving categories. Attackers can...

CVE-2021-32615

CRITICAL CVSS 9.8 May 13, 2021

This vulnerability allows authenticated administrators in Piwigo 11.4.0 to perform SQL injection attacks via the order[0][dir] parameter in admin/user_list_backend.php. Attackers can potentially execu...

CVE-2024-48928

HIGH CVSS 7.5 Feb 24, 2026

Piwigo versions 14.x have a weak secret key generation vulnerability during installation. Attackers can brute-force the secret key in about one hour, potentially bypassing CSRF protection and generati...

CVE-2025-62406

HIGH CVSS 8.1 Nov 18, 2025

This vulnerability in Piwigo allows attackers to send password reset emails containing malicious links to legitimate users. By manipulating the Host header in HTTP requests, attackers can redirect use...

CVE-2023-37270

HIGH CVSS 7.6 Jul 7, 2023

Piwigo photo gallery software versions before 13.8.0 contain a SQL injection vulnerability in the administrator login screen. Attackers with any administrator access can execute arbitrary SQL statemen...

CVE-2023-27233

HIGH CVSS 8.8 May 17, 2023

CVE-2023-27233 is a SQL injection vulnerability in Piwigo's user_list_backend.php file that allows attackers to execute arbitrary SQL commands via the order[0][dir] parameter. This affects all Piwigo ...

CVE-2023-26876

HIGH CVSS 8.8 Apr 21, 2023

This SQL injection vulnerability in Piwigo allows remote attackers to execute arbitrary SQL commands via the filter_user_id parameter in the admin.php endpoint. Attackers could potentially read, modif...

CVE-2022-32297

HIGH CVSS 7.5 Jul 14, 2022

CVE-2022-32297 is a SQL injection vulnerability in Piwigo's search function that allows attackers to execute arbitrary SQL commands. This affects Piwigo v12.2.0 installations, potentially compromising...

CVE-2021-40553

HIGH CVSS 8.8 Jun 28, 2022

CVE-2021-40553 is a remote code execution vulnerability in Piwigo's LocalFiles Editor that allows attackers to execute arbitrary code on affected systems. This affects Piwigo 11.5.0 installations with...

CVE-2021-40317

HIGH CVSS 8.8 May 26, 2022

CVE-2021-40317 is a SQL injection vulnerability in Piwigo's admin.php file via the id parameter. This allows authenticated attackers to execute arbitrary SQL commands on the database. Only Piwigo admi...

CVE-2020-19216

HIGH CVSS 8.8 May 6, 2022

This CVE describes an SQL injection vulnerability in Piwigo's admin/user_perm.php file via the cat_false parameter. Attackers can execute arbitrary SQL commands on the database, potentially compromisi...

CVE-2022-26267

HIGH CVSS 7.5 Mar 18, 2022

Piwigo v12.2.0 contains an information disclosure vulnerability in the admin maintenance actions page. Attackers can exploit this to leak sensitive information from the application. Only Piwigo instal...

CVE-2016-3735

HIGH CVSS 8.1 Jan 28, 2022

CVE-2016-3735 is a predictable password reset token vulnerability in Piwigo image gallery software. When certain criteria aren't met, Piwigo uses PHP's mt_rand() function to generate password reset to...

CVE-2021-27973

HIGH CVSS 7.2 Apr 2, 2021

This SQL injection vulnerability in Piwigo allows attackers to execute arbitrary SQL commands via the language parameter in the admin.php?page=languages endpoint. It affects Piwigo installations befor...

CVE-2024-46606

MEDIUM CVSS 5.4 Oct 16, 2024

A stored cross-site scripting (XSS) vulnerability in Piwigo's photo description field allows attackers to inject malicious scripts that execute when administrators view the affected page. This affects...

CVE-2024-46333

MEDIUM CVSS 4.8 Sep 27, 2024

An authenticated cross-site scripting (XSS) vulnerability in Piwigo v14.5.0 allows attackers with album creation permissions to inject malicious scripts into album names. When other users view these a...