Piwigo
110 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Piwigo, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.
Piwigo CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 3 |
| 2024-11 | 1 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 1 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 1 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 4 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 1 |
| 2026-08 | 0 |
| 2026-09 | 6 |
Severity
How the 110 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical14
- High37
- Medium59
Latest CVEs
The 15 most recently published vulnerabilities affecting Piwigo.
- CVE-2026-42322Piwigo: Authenticated RCE via File Upload in Logo Upload Feature9.1
- CVE-2026-42324Piwigo: Second-Order SQL Injection7.2
- CVE-2026-44642Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorization bypass (PHP 8+)8.1
- CVE-2026-62262Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`9.1
- CVE-2026-42323Piwigo: SQL Injection in Batch Manager7.2
- CVE-2026-85750Piwigo arbitrary file read and remote code execution via insecure image processing7.2
- CVE-2026-35048Piwigo RCE via PHP Code Injection into Config File in Installer9.8
- CVE-2026-27885Piwigo: SQL Injection in Activity.getList7.2
- CVE-2026-27834Piwigo: SQL Injection in pwg.users.getList API Method via filter Parameter7.2
- CVE-2026-27833Piwigo: Unauthenticated Information Disclosure via pwg.history.search API7.5
- CVE-2026-27634Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter9.8
- CVE-2025-62512Piwigo Vulnerable to User Enumeration via Password Reset Endpoint5.3
- CVE-2024-48928Piwigo's secret key can be brute forced7.5
- CVE-2025-62406Piwigo is vulnerable to one-click account takeover by modifying the password-reset link8.1
- CVE-2024-43018Piwigo 13.8.0 and below is vulnerable to SQL Injection in the parameters max_level and min_register. These parameters are used in ws_user_gerList function from file include\ws_functions\pwg.users.p...6.4
Product grouping is registry-driven, with AI assist and human review. How it works