Security Advisory

CVE-2026-27833

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-04-03 21:34:11
Last updated 2026-04-06 18:55:09
Assigner GitHub_M
State PUBLISHED

Description

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.