CVE-2026-27833

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) Piwigo es una aplicación de galería de fotos de código abierto para la web. Antes de la versión 16.3.0, el método API pwg.history.search en Piwigo está registrado sin la opción admin_only, permitiendo a usuarios no autenticados acceder al historial de navegación completo de todos los visitantes de la galería. Este problema ha sido parcheado en la versión 16.3.0.

09 Apr 2026, 21:14

Type Values Removed Values Added
References () https://github.com/Piwigo/Piwigo/commit/d05c16561ce3692ca922199f8c8d7b1a45893f1c - () https://github.com/Piwigo/Piwigo/commit/d05c16561ce3692ca922199f8c8d7b1a45893f1c - Patch
References () https://github.com/Piwigo/Piwigo/security/advisories/GHSA-397m-gfhm-pmg2 - () https://github.com/Piwigo/Piwigo/security/advisories/GHSA-397m-gfhm-pmg2 - Exploit, Vendor Advisory
References () https://piwigo.org/release-16.3.0 - () https://piwigo.org/release-16.3.0 - Release Notes
First Time Piwigo
Piwigo piwigo
CPE cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*

03 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 22:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-27833

Mitre link : CVE-2026-27833

CVE.ORG link : CVE-2026-27833


JSON object : View

Products Affected

piwigo

  • piwigo
CWE
CWE-862

Missing Authorization