Executive brief
Piwigo is an open-source photo gallery application used to manage and display image collections online. A security flaw allows anyone on the internet to access the private browsing history of all gallery visitors without needing a password. This could lead to the exposure of visitor IP addresses, usernames, and details about which specific images were viewed or downloaded.
Technical details
A missing authorization check (CWE-862) exists in the Piwigo web API. The 'pwg.history.search' method in 'ws.php' was registered without the 'admin_only' flag, and the corresponding handler function 'ws_history_search()' in 'include/ws_functions/pwg.php' lacked manual authentication checks. An unauthenticated remote attacker can exploit this by sending a crafted HTTP request to the API to retrieve sensitive information, including visitor IP addresses, user IDs, image viewing/download history, and search queries. The vulnerability is resolved in version 16.3.0 by properly enforcing administrative restrictions on the affected API endpoint.
Affected products
- Piwigo Piwigo < 16.3.0
Timeline
- 2026-02-24: patched: Version 16.3.0 released
- 2026-04-01: advisory: GitHub Security Advisory published
- 2026-04-03: disclosed: CVE published to NVD