plegall
16 exploits
Active since Jan 2017
Piwigo < 2.8.3 - Unauthenticated Exposure of Sensitive Information via admin/plugin.php
CVSS 9.8
Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter
CVSS 9.8
Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
CVSS 7.5
Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter
CVSS 7.2
Piwigo: SQL Injection in Activity.getList
CVSS 7.2
Piwigo 14.x - Weak Secret Key Vulnerability
CVSS 7.5
Piwigo 2.9.2 - SQL Injection via List Users API sSortDir_0 Parameter
CVSS 4.9
Piwigo 2.9.2 - SQL Injection via Configuration Order By Parameter
CVSS 4.9
Piwigo 2.9.2 - SQL Injection via Batch Manager Unit Mode element_ids Parameter
CVSS 4.9
Piwigo 2.9.2 - Cross-Site Request Forgery via Admin Configuration or Batch Manager
CVSS 8.8
Piwigo < 2.8.6 - Cross-Site Scripting via Image Filename Upload
CVSS 6.1
Piwigo < 2.9.0 - Authenticated SQL Injection via iDisplayStart and iDisplayLength Parameters
CVSS 6.5
LocalFilesEditor < 11.4.0.1 - Local File Inclusion via show_default.php file Parameter
CVSS 7.5
Piwigo 11.4.0 - SQL Injection via order[0][dir] Parameter
CVSS 9.8
Piwigo < 14.0.0beta4 - Reflected Cross-Site Scripting via plugin_id Parameter
CVSS 9.3
Piwigo < 14.3.0 - Cross-Site Scripting in create_tag Function
CVSS 5.4