CVE-2014-1980
Piwigo <2.4.6 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in include/functions_metadata.inc.php in Piwigo before 2.4.6 allows remote attackers to inject arbitrary web script or HTML via the Make field in IPTC Exif metadata within an image uploaded to the Community plugin.
Scores
EPSS
0.0030
EPSS Percentile
52.8%
Details
CWE
CWE-79
Status
published
Products (37)
piwigo/piwigo
< 2.4.5
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
piwigo/piwigo
... and 27 more
Published
Aug 14, 2014
Tracked Since
Feb 18, 2026