Junglewise Threat Intelligence

CVE-2026-78187: Piwigo reflected XSS in public authentication page

CVE-2026-78187 · Severity: low · CVSS 3.1 · Published 2026-08-24

Technologies: Piwigo. Vendors: Piwigo.

Executive brief

Piwigo is an open-source photo gallery and management application. A reflected cross-site scripting (XSS) vulnerability in the public authentication page allows attackers to inject malicious scripts through the lang parameter, which could be used to steal session cookies, credentials, or perform actions on behalf of logged-in users if they click a crafted link.

Technical details

This is a reflected XSS vulnerability in Piwigo's Public Authentication Page component, specifically in how it handles the 'lang' argument. The vulnerability stems from insufficient input validation or output encoding of the lang parameter. The attack is network-based and requires high complexity (likely user interaction, such as clicking a malicious link), but no authentication is required to exploit it. An attacker can inject arbitrary JavaScript code that executes in the victim's browser within the context of the Piwigo application. The vulnerability has been patched in version 16.4.0 (commit 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e), and users should upgrade immediately.

Affected products

  • Piwigo Piwigo 16.3.0

Timeline

  • 2026-08-24: disclosed

References

Related threats