Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Piwigo

First CVE: Aug 21, 2009Active for: 17 yearsTotal CVEs: 114
49.3
VTI Score
High

Piwigo is a widely embedded open-source photo gallery and media-management platform whose exposure reaches far beyond its modest product count through deep integration into self-hosted and community-driven deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the platform's appeal as a target for both reconnaissance and post-compromise persistence. The exposure recurs across its core gallery product and plugins such as Lexiglot, Guestbook, and LocalFiles Editor through a durable pattern of web-application weaknesses—principally cross-site scripting, SQL injection, cross-site request forgery, and improper access control—that are characteristic of community-maintained PHP-based applications with frequent user-facing input surfaces. Defenders should treat Piwigo instances as security-sensitive and prioritize patching, since the platform often runs in less-monitored environments where updates lag; live severity and exploitation activity are shown alongside this summary.

FAUCET AI Generated
114
Total CVEs
More Total CVEs than 99% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Piwigo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 2009
16 years ago
Most Recent CVE
Apr 3, 2026
112 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (114 CVEs).

114 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-1469MEDIUM
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
Mar 13, 20134.049NOYES
CVE-2017-10682CRITICAL
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in t
Jun 29, 20179.845NOYES
CVE-2023-33362CRITICAL
Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.
May 23, 20239.844NOYES
CVE-2023-26876HIGH
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&fi
Apr 21, 20238.843NOYES
CVE-2020-9467MEDIUM
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
Mar 26, 20205.441NOYES
CVE-2021-27973HIGH
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
Apr 2, 20217.239NOYES
CVE-2023-37270HIGH
Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acqui
Jul 7, 20238.837NOYES
CVE-2026-27833HIGH
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, al
Apr 3, 20267.536NOYES
CVE-2026-27634CRITICAL
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_cre
Apr 3, 20269.835NONO
CVE-2012-2208HIGH
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language para
Aug 14, 20127.534NOYES
View all 114 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products114 CVEs
55%
34%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (0.9%)
Network95 (83.3%)
Unknown18 (15.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low94 (82.5%)
High2 (1.8%)
Unknown18 (15.8%)
User Interaction
None47 (41.2%)
Unknown18 (15.8%)
Required49 (43.0%)
Privileges Required
Low29 (25.4%)
High14 (12.3%)
None53 (46.5%)
Unknown18 (15.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (114 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
0.9% of CVEs· 97th percentile
Nuclei
4 CVEs
3.5% of CVEs· 95th percentile
ExploitDB
12 CVEs
10.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Piwigo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Piwigo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Piwigo's Products

View all 5 CNAs →

Top CWEs