| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-27885 | Piwigo: SQL Injection in Activity.getList | Piwigo | Piwigo | High | 7.2 | 2026-04-03 21:36:07 | Deep Dive |
| CVE-2026-27834 | Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter | Piwigo | Piwigo | High | 7.2 | 2026-04-03 21:35:14 | Deep Dive |
| CVE-2026-27833 | Piwigo: Unauthenticated Information Disclosure via pwg.history.search API | Piwigo | Piwigo | High | 7.5 | 2026-04-03 21:34:11 | Deep Dive |
| CVE-2026-27634 | Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter | Piwigo | Piwigo | - | - | 2026-04-03 21:33:14 | Deep Dive |
| CVE-2025-62512 | Piwigo Vulnerable to User Enumeration via Password Reset Endpoint | Piwigo | Piwigo | 中危 | - | 2026-02-24 16:43:29 | Deep Dive |
| CVE-2024-48928 | Piwigo's secret key can be brute forced | Piwigo | Piwigo | 高危 | - | 2026-02-24 16:39:57 | Deep Dive |
| CVE-2025-62406 | Piwigo is vulnerable to one-click account takeover by modifying the password-reset link | Piwigo | Piwigo | High | 8.1 | 2025-11-18 22:18:46 | Deep Dive |
| CVE-2023-44393 | Piwigo Reflected XSS vulnerability | Piwigo | Piwigo | Critical | 9.3 | 2023-10-09 14:52:43 | Deep Dive |
| CVE-2023-37270 | Piwigo SQL Injection vulnerability in "User-Agent" | Piwigo | Piwigo | High | 7.6 | 2023-07-07 21:26:29 | Deep Dive |
| CVE-2014-125053 | Piwigo-Guest-Book Navigation Bar guestbook.inc.php sql injection | - | Piwigo-Guest-Book | Medium | 5.5 | 2023-01-06 22:44:36 | Deep Dive |
| CVE-2016-3735 | Piwigo 安全漏洞 | - | Piwigo | 高危 | - | 2022-01-28 00:00:00 | Deep Dive |
| CVE-2012-4526 | Piwigo 跨站脚本漏洞 | piwigo | piwigo | 中危 | - | 2019-12-02 17:48:45 | Deep Dive |
| CVE-2012-4525 | Piwigo 跨站脚本漏洞 | piwigo | piwigo | 中危 | - | 2019-12-02 17:46:59 | Deep Dive |