Vulnerabilities > Piwigo > Piwigo > 2.1.5

DATE CVE VULNERABILITY TITLE RISK
2017-10-10 CVE-2016-10514 Improper Access Control vulnerability in Piwigo
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.
network
piwigo CWE-284
4.3
2017-10-10 CVE-2016-10513 Cross-site Scripting vulnerability in Piwigo
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
network
piwigo CWE-79
4.3
2017-06-29 CVE-2017-10682 SQL Injection vulnerability in Piwigo
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
network
low complexity
piwigo CWE-89
7.5
2017-06-29 CVE-2017-10681 Cross-Site Request Forgery (CSRF) vulnerability in Piwigo
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to unlock albums via a crafted request.
network
piwigo CWE-352
6.8
2017-06-29 CVE-2017-10680 Cross-Site Request Forgery (CSRF) vulnerability in Piwigo
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to change a private album to public via a crafted request.
network
piwigo CWE-352
6.8
2017-06-29 CVE-2017-10679 Information Exposure vulnerability in Piwigo
Piwigo through 2.9.1 allows remote attackers to obtain sensitive information about the descriptive name of a permalink by examining the redirect URL that is returned in a request for the permalink ID number of a private album.
network
low complexity
piwigo CWE-200
5.0
2017-06-29 CVE-2017-10678 Cross-Site Request Forgery (CSRF) vulnerability in Piwigo
Cross-site request forgery (CSRF) vulnerability in Piwigo through 2.9.1 allows remote attackers to hijack the authentication of users for requests to delete permalinks via a crafted request.
network
piwigo CWE-352
6.8
2017-06-14 CVE-2017-9464 Open Redirect vulnerability in Piwigo
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks.
network
piwigo CWE-601
5.8
2017-06-14 CVE-2017-9463 SQL Injection vulnerability in Piwigo
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior.
network
low complexity
piwigo CWE-89
4.0
2017-06-06 CVE-2017-9452 Cross-site Scripting vulnerability in Piwigo
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
network
piwigo CWE-79
3.5