RSS   Podatności dla 'Piwigo'   RSS

2021-12-14
 
CVE-2021-40882

CWE-79
 

 
A Cross Site Scripting (XSS) vulnerability exists in Piwigo 11.5.0 via the system album name and description of the location.

 
2021-12-06
 
CVE-2021-40313

CWE-89
 

 
Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.

 
2021-07-21
 
CVE-2020-22148

CWE-79
 

 
A stored cross site scripting (XSS) vulnerability in /admin.php?page=tags of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.

 
 
CVE-2020-22150

CWE-79
 

 
A cross site scripting (XSS) vulnerability in /admin.php?page=permalinks of Piwigo 2.10.1 allows attackers to execute arbitrary web scripts or HTML.

 
2021-05-13
 
CVE-2021-32615

CWE-89
 

 
Piwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.

 
2021-04-02
 
CVE-2021-27973

CWE-89
 

 
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.

 
2020-03-26
 
CVE-2020-9468

CWE-20
 

 
The Community plugin 2.9.e-beta for Piwigo allows users to set image information on images in albums for which they do not have permission, by manipulating the image_id parameter.

 
 
CVE-2020-9467

CWE-79
 

 
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.

 
2020-02-10
 
CVE-2020-8089

CWE-79
 

 
Piwigo 2.10.1 is affected by stored XSS via the Group Name Field to the group_list page.

 
2019-12-02
 
CVE-2012-4526

CWE-79
 

 
piwigo has XSS in password.php (incomplete fix for CVE-2012-4525)

 


Copyright 2022, cxsecurity.com

 

Back to Top