CVE-2016-10514: Piwigo
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.
Affected products
- Piwigo Piwigo: up to and including 2.8.2
Published 2017-10-10. Last modified 2026-06-17.