CVE-2026-78187: Piwigo Public Authentication cross site scripting
A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 16.4.0 will fix this issue. The name of the patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e. It is recommended to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Piwigoto a version that resolves this vulnerability.Fixed in 16.4.0Patch 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e - Compensating control
If immediate upgrade to Piwigo 16.4.0 is not possible, restrict/rate-limit access to the Piwigo public authentication page to reduce exposure to remote exploitation.
Event History
Frequently Asked Questions
What versions should be prioritized for remediation?
Piwigo 16.3.0 is identified as affected. Upgrade to version 16.4.0, which fixes the issue; the referenced patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e.
What does exploitation require?
Exploitation can be performed remotely without privileges, but requires user interaction and is rated high complexity. The attack involves manipulating the lang argument on the Public Authentication Page.
Is there public exploit availability?
Yes. The exploit has been publicly disclosed and may be used, although the issue is described as difficult to exploit.