CVE-2018-5692: Piwigo

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Piwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.

Affected products

  • Piwigo Piwigo: version 2.8.2 only

Published 2018-01-14. Last modified 2026-06-17.