A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversal. Remote exploitation of the attack is
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Piwigo | 16.0 |
cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84430 | 6.3 MEDIUM | gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes |
| CVE-2026-84438 | 3.5 LOW | OpenCart Autocomplete Workflow edit.php cross site scripting |
| CVE-2026-84437 | 3.5 LOW | OpenCart Autocomplete Workflow address.php cross site scripting |
No comments yet