VulnSea

Piwigo vulnerabilities

CVEs whose affected-version data names the Piwigo package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

6 CVEsRSS

CVE-2026-42324High· 7.2PoC
today

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The store…

▾ MidnightPiwigo · Piwigovia NVD
CVE-2026-62262Critical· 9.1
today

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then o…

▾ MidnightPiwigo · Piwigovia NVD
CVE-2026-42323High· 7.2
today

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager f…

▾ TwilightPiwigo · Piwigovia NVD
CVE-2026-44642High· 8.1PoC
today

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_mag…

▾ MidnightPiwigo · Piwigovia NVD
CVE-2026-42322Critical· 9.1
today

Piwigo is a full featured open source photo gallery application for the web

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo whe…

▾ MidnightPiwigo · Piwigovia NVD
CVE-2026-85750High· 7.2PoC
today

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files

Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing fo…

▾ MidnightPiwigo · Piwigovia NVD
Piwigo vulnerabilities (CVEs) · VulnSea