CVE-2026-27833 impacts Piwigo photo gallery applications prior to version 16.3.0, enabling unauthenticated users to access the complete browsing history of all gallery visitors via the `pwg.history.search` API method. This vulnerability carries a CVSS score of 7.5 (High), indicating a critical confidentiality impact due to its network attack vector, low complexity, and lack of required privileges or user interaction. While public exploit code is not currently available in Metasploit, Nuclei, or ExploitDB, and it is not listed in CISA's KEV catalog, there have been minimal community discussions. Organizations using Piwigo are strongly advised to upgrade to version 16.3.0 or later to remediate this exposure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.3.0CPE matchmatch criteria | cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.