← Terug naar overzicht

A path traversal vulnerability has been identified in Piwigo versions up to 16.3.0, affecting the i.php file within the Image Derivative Handler component. The flaw allows remote attackers to manipulate file paths, potentially accessing unauthorized files on the server. No authentication appears to be required to exploit the vulnerability, as indicated by the PoC title referencing 'unauthenticated' access. A public exploit has been disclosed on GitHub, increasing the risk of active exploitation. The vulnerability is remotely exploitable, making it a significant security concern for Piwigo installations. Users of Piwigo up to version 16.3.0 are advised to apply patches or mitigations promptly. The issue has been catalogued on NVD, VulDB, and supported by a proof-of-concept repository.

Affected products

  • Piwigo up to 16.3.0

Related CVE's

  • CVE-2026-84441

Categories

  • Web Technologies
  • Zero-Day Vulnerabilities