HarborGuard / CVE
Back to search
HIGHCVE-2026-27833Published Modified CNA GitHub_M

CVE-2026-27833: Piwigo: Unauthenticated Information Disclosure via pwg.history.search API

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Piwigo / Piwigo
    < 16.3.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE-2026-27833: Piwigo: Unauthenticated Information Disclosure via pwg.history.search API | HarborGuard CVE