Vulnerabilities > Piwigo > Lexiglot > High

DATE CVE VULNERABILITY TITLE RISK
2020-06-01 CVE-2014-8943 Server-Side Request Forgery (SSRF) vulnerability in Piwigo Lexiglot
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
network
low complexity
piwigo CWE-918
8.8
2020-06-01 CVE-2014-8942 Cross-Site Request Forgery (CSRF) vulnerability in Piwigo Lexiglot
Lexiglot through 2014-11-20 allows CSRF.
network
low complexity
piwigo CWE-352
8.8
2020-06-01 CVE-2014-8938 Insufficiently Protected Credentials vulnerability in Piwigo Lexiglot
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.
local
low complexity
piwigo CWE-522
7.8
2020-06-01 CVE-2014-8937 Resource Exhaustion vulnerability in Piwigo Lexiglot
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.
network
low complexity
piwigo CWE-400
7.5