Piwigo

Piwigo is a photo gallery software for the web built by an active community of users and developers. Extensions make Piwigo easily customizable. Icing on the cake Piwigo is free and opensource.

Severity Summary:

Critical: 9 High: 27 Medium: 51
Reference
Title
Severity
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Cross-Site Request Forgery (CSRF) Vulnerability
Medium
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
Piwigo Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Piwigo Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Medium
Piwigo URL Redirection to Untrusted Site (Open Redirect) Vulnerability
Medium
Piwigo Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium