Vulnerabilities > Piwigo > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-12-21 CVE-2017-17823 SQL Injection vulnerability in Piwigo 2.9.2
The Configuration component of Piwigo 2.9.2 is vulnerable to SQL Injection via the admin/configuration.php order_by array parameter.
network
low complexity
piwigo CWE-89
4.9
2017-12-21 CVE-2017-17822 SQL Injection vulnerability in Piwigo 2.9.2
The List Users API of Piwigo 2.9.2 is vulnerable to SQL Injection via the /admin/user_list_backend.php sSortDir_0 parameter.
network
low complexity
piwigo CWE-89
4.9
2017-12-20 CVE-2017-17775 Cross-site Scripting vulnerability in Piwigo 2.9.2
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
network
low complexity
piwigo CWE-79
6.1
2017-12-01 CVE-2017-16893 SQL Injection vulnerability in Piwigo
The application Piwigo is affected by an SQL injection vulnerability in version 2.9.2 and possibly prior.
network
low complexity
piwigo CWE-89
6.5
2017-10-10 CVE-2016-10514 Improper Access Control vulnerability in Piwigo
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.
network
low complexity
piwigo CWE-284
6.5
2017-10-10 CVE-2016-10513 Cross-site Scripting vulnerability in Piwigo
Cross Site Scripting (XSS) exists in Piwigo before 2.8.3 via a crafted search expression to include/functions_search.inc.php.
network
low complexity
piwigo CWE-79
6.1
2017-06-24 CVE-2017-9836 Cross-site Scripting vulnerability in Piwigo 2.9.1
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).
network
low complexity
piwigo CWE-79
4.8
2017-06-14 CVE-2017-9464 Open Redirect vulnerability in Piwigo
An open redirect vulnerability is present in Piwigo 2.9 and probably prior versions, allowing remote attackers to redirect users to arbitrary web sites and conduct phishing attacks.
network
low complexity
piwigo CWE-601
6.1
2017-06-14 CVE-2017-9463 SQL Injection vulnerability in Piwigo
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior.
network
low complexity
piwigo CWE-89
6.5
2017-06-06 CVE-2017-9452 Cross-site Scripting vulnerability in Piwigo
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
network
low complexity
piwigo CWE-79
4.8