CVE-2026-27833
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.
Vendor
-
Product
-
CWE
Yayın Tarihi
2026-04-03 22:16:25
Güncelleme
2026-04-07 13:20:55
Source Identifier
security-advisories@github.com
KEV Date Added
-