CVE-2017-9452
MEDIUMPiwigo <2.9.0 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Scores
CVSS v3
4.8
EPSS
0.0017
EPSS Percentile
38.2%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
piwigo/piwigo
< 2.9.0
n/a/n/a
Published
Jun 06, 2017
Tracked Since
Feb 18, 2026