Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-7723
The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.phppagecat_list request a different issue than CVE-2017-9836. CSRF exploitation related to CVE-2017-10681 may be possible.