Piwigo has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 6. The median CVSS is 7.7 (high), with 2 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-89 (4).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.7
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-44642High· 8.1Piwigo is a full featured open source photo gallery application for the web57CVE-2026-85750High· 7.2Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files52CVE-2026-42324High· 7.2Piwigo is a full featured open source photo gallery application for the web52CVE-2026-62262Critical· 9.1Piwigo is a full featured open source photo gallery application for the web50CVE-2026-42322Critical· 9.1Piwigo is a full featured open source photo gallery application for the web50
Piwigo vulnerabilities
CVEs affecting Piwigo, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-42324High· 7.2PoCPiwigo is a full featured open source photo gallery application for the web
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The store…
CVE-2026-62262Critical· 9.1Piwigo is a full featured open source photo gallery application for the web
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then o…
CVE-2026-42323High· 7.2Piwigo is a full featured open source photo gallery application for the web
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager f…
CVE-2026-44642High· 8.1PoCPiwigo is a full featured open source photo gallery application for the web
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_mag…
CVE-2026-42322Critical· 9.1Piwigo is a full featured open source photo gallery application for the web
Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_pages.php validates uploaded logo content by MIME type but reuses the attacker-controlled extension from std_pgs_logo whe…
CVE-2026-85750High· 7.2PoCPiwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files
Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. By abusing fo…