CVE-2017-9425: Facetag Project Facetag

Medium severity, CVSS 6.1. EPSS: 1.4% chance of exploitation in the next 30 days.

The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.

Affected products

Published 2018-02-26. Last modified 2026-06-17.