CVE-2026-27833

HIGH

Piwigo: Unauthenticated Information Disclosure via pwg.history.search API

Title source: cna

Description

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.

Scores

CVSS v3 7.5
EPSS 0.0004
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-862
Status published
Products (2)
piwigo/piwigo < 16.3.0
Piwigo/Piwigo < 16.3.0
Published Apr 03, 2026
Tracked Since Apr 04, 2026