Piwigo is a widely embedded open-source photo gallery and media-management platform whose exposure reaches far beyond its modest product count through deep integration into self-hosted and community-driven deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the platform's appeal as a target for both reconnaissance and post-compromise persistence. The exposure recurs across its core gallery product and plugins such as Lexiglot, Guestbook, and LocalFiles Editor through a durable pattern of web-application weaknesses—principally cross-site scripting, SQL injection, cross-site request forgery, and improper access control—that are characteristic of community-maintained PHP-based applications with frequent user-facing input surfaces. Defenders should treat Piwigo instances as security-sensitive and prioritize patching, since the platform often runs in less-monitored environments where updates lag; live severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Piwigo over time
Signals from CVEs in this vendor scope (114 CVEs).
114 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-1469MEDIUM Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter. | Mar 13, 2013 | 4.0 | 49 | NO | YES |
CVE-2017-10682CRITICAL SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in t | Jun 29, 2017 | 9.8 | 45 | NO | YES |
CVE-2023-33362CRITICAL Piwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function. | May 23, 2023 | 9.8 | 44 | NO | YES |
CVE-2023-26876HIGH SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&fi | Apr 21, 2023 | 8.8 | 43 | NO | YES |
CVE-2020-9467MEDIUM Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function. | Mar 26, 2020 | 5.4 | 41 | NO | YES |
CVE-2021-27973HIGH SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages. | Apr 2, 2021 | 7.2 | 39 | NO | YES |
CVE-2023-37270HIGH Piwigo is open source photo gallery software. Prior to version 13.8.0, there is a SQL Injection vulnerability in the login of the administrator screen. The SQL statement that acqui | Jul 7, 2023 | 8.8 | 37 | NO | YES |
CVE-2026-27833HIGH Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, al | Apr 3, 2026 | 7.5 | 36 | NO | YES |
CVE-2026-27634CRITICAL Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_cre | Apr 3, 2026 | 9.8 | 35 | NO | NO |
CVE-2012-2208HIGH Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language para | Aug 14, 2012 | 7.5 | 34 | NO | YES |
Signals from CVEs in this vendor scope (114 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Piwigo.
Media articles that mention a CVE ID that affects a product developed by Piwigo — matched by CVE ID, not by vendor name.