flop25
4 exploits
Active since Jun 2017
Piwigo < 2.9.1 - SQL Injection via cat_false or cat_true Parameter
CVSS 9.8
Piwigo <= 2.9.1 - Cross-Site Request Forgery via Permalink Deletion
CVSS 8.8
Piwigo <= 2.9.1 - Cross-Site Request Forgery via Album Privacy Change
CVSS 8.8
Piwigo <= 2.9.1 - Cross-Site Request Forgery via Album Unlock Request
CVSS 8.8