Vulnerabilities (CVE)

Filtered by vendor Piwigo Subscribe
Filtered by product Piwigo
Total 103 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2010-1707 1 Piwigo 1 Piwigo 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.
CVE-2009-4039 1 Piwigo 1 Piwigo 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2009-2933 1 Piwigo 1 Piwigo 2026-06-16 7.5 HIGH N/A
SQL injection vulnerability in comments.php in Piwigo before 2.0.3 allows remote attackers to execute arbitrary SQL commands via the items_number parameter.