CVE-2026-78187: Piwigo Public Authentication cross site scripting

Published Aug 24, 2026
·
Updated

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 16.4.0 will fix this issue. The name of the patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e. It is recommended to upgrade the affected component.

Affected Software

1 affected component
Piwigo piwigo=16.3.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Piwigo to a version that resolves this vulnerability.

    Fixed in 16.4.0Patch 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e
  2. Compensating control

    If immediate upgrade to Piwigo 16.4.0 is not possible, restrict/rate-limit access to the Piwigo public authentication page to reduce exposure to remote exploitation.

Event History

Aug 24, 2026
CVE Published
via MITRE·04:30 AM
Data Sourced
via MITRE·04:30 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What versions should be prioritized for remediation?

Piwigo 16.3.0 is identified as affected. Upgrade to version 16.4.0, which fixes the issue; the referenced patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e.

2

What does exploitation require?

Exploitation can be performed remotely without privileges, but requires user interaction and is rated high complexity. The attack involves manipulating the lang argument on the Public Authentication Page.

3

Is there public exploit availability?

Yes. The exploit has been publicly disclosed and may be used, although the issue is described as difficult to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203