Piwigo

Piwigo is a photo gallery software for the web built by an active community of users and developers. Extensions make Piwigo easily customizable. Icing on the cake Piwigo is free and opensource.

Severity Summary:

Critical: 9 High: 27 Medium: 51
Reference
Title
Severity
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Critical
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
Critical
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Piwigo Vulnerability
Critical
Piwigo Improper Access Control Vulnerability
Critical
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
High
Piwigo Improper Access Control Vulnerability
High
Piwigo Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Exposure of Resource to Wrong Sphere Vulnerability
High
Piwigo Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) Vulnerability
High
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Access Control Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
High
Piwigo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
High
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
High