plegall
15 exploits
Active since Jan 2017
Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter
CVSS 9.8
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
CVSS 7.5
Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter
CVSS 7.2
Piwigo: SQL Injection in Activity.getList
CVSS 7.2
Piwigo 14.x - Weak Secret Key Vulnerability
CVSS 7.5
Piwigo - SQL Injection
CVSS 4.9
Piwigo - SQL Injection
CVSS 4.9
Piwigo - SQL Injection
CVSS 4.9
Piwigo - CSRF
CVSS 8.8
Piwigo < 2.8.5 - XSS
CVSS 6.1
Piwigo 2.9.0 - SQL Injection
CVSS 6.5
Piwigo Localfiles Editor < 11.4.0.1 - Data Authenticity Bypass
CVSS 7.5
Piwigo - SQL Injection
CVSS 9.8
Piwigo < 13.8.0 - Basic XSS
CVSS 9.3
Piwigo - XSS
CVSS 5.4