Skip to content

Known CVE

Piwigo < 16.3.0 - Unauthenticated Information Disclosure via History API

Piwigo <= 16.3.0 contains an information disclosure vulnerability caused by the pwg.history.search API method lacking admin_only restriction, letting unauthenticated users access full browsing history, exploit requires no authentication

CVE-2026-27833

High2026CVSS 7.5CWE-862

cve2026 · piwigo · exposure · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website