← לוח פגיעויות

CVE-2026-27833

גבוהה 7.5

תיאור (מקור, אנגלית)

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.

מדדים

CVSS 3.1
7.5 (HIGH) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS — סבירות ניצול
2% (אחוזון 100) נכון ל-24/9/2026
CWE
CWE-862

מוצרים מושפעים

piwigo: piwigo

קישורים