Show filters
99 Total Results
Displaying 11-20 of 99
Sort by:
Attacker Value
Unknown

CVE-2014-125053

Disclosure Date: January 06, 2023 (last updated October 20, 2023)
A vulnerability was found in Piwigo-Guest-Book up to 1.3.0. It has been declared as critical. This vulnerability affects unknown code of the file include/guestbook.inc.php of the component Navigation Bar. The manipulation of the argument start leads to sql injection. Upgrading to version 1.3.1 is able to address this issue. The patch is identified as 0cdd1c388edf15089c3a7541cefe7756e560581d. It is recommended to upgrade the affected component. VDB-217582 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-37183

Disclosure Date: August 31, 2022 (last updated October 08, 2023)
Piwigo 12.3.0 is vulnerable to Cross Site Scripting (XSS) via /search/1940/created-monthly-list.
Attacker Value
Unknown

CVE-2022-32297

Disclosure Date: July 14, 2022 (last updated October 07, 2023)
Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.
Attacker Value
Unknown

CVE-2021-40553

Disclosure Date: June 28, 2022 (last updated October 07, 2023)
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
Attacker Value
Unknown

CVE-2021-40678

Disclosure Date: June 14, 2022 (last updated October 07, 2023)
In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.
Attacker Value
Unknown

CVE-2021-40317

Disclosure Date: May 26, 2022 (last updated October 07, 2023)
Piwigo 11.5.0 is affected by a SQL injection vulnerability via admin.php and the id parameter.
Attacker Value
Unknown

CVE-2020-19217

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
SQL Injection vulnerability in admin/batch_manager.php in piwigo v2.9.5, via the filter_category parameter to admin.php?page=batch_manager.
Attacker Value
Unknown

CVE-2020-19216

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.
Attacker Value
Unknown

CVE-2020-19215

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=user_perm.
Attacker Value
Unknown

CVE-2020-19213

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.