CVE-2026-27833
HIGH NUCLEIPiwigo: Unauthenticated Information Disclosure via pwg.history.search API
Title source: cnaExploitation Summary
CVE-2026-27833 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.
Nuclei Templates (1)
Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History API
HIGHby 0x_Akoko
FOFA:
icon_hash=="540706145"
References (3)
Core 3
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/Piwigo/Piwigo/security/advisories/GHSA-397m-gfhm-pmg2
X_Refsource_Misc x_refsource_misc
https://github.com/Piwigo/Piwigo/commit/d05c16561ce3692ca922199f8c8d7b1a45893f1c
X_Refsource_Misc x_refsource_misc
https://piwigo.org/release-16.3.0
Scores
CVSS v3
7.5
EPSS
0.0123
EPSS Percentile
65.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-862
Status
published
Products (2)
piwigo/piwigo
< 16.3.0
Piwigo/Piwigo
< 16.3.0
Published
Apr 03, 2026
Tracked Since
Apr 04, 2026