Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 03 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the pwg.history.search API method in Piwigo is registered without the admin_only option, allowing unauthenticated users to access the full browsing history of all gallery visitors. This issue has been patched in version 16.3.0.
Title Piwigo: Unauthenticated Information Disclosure via pwg.history.search API
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-04-03T21:34:11.425Z

Reserved: 2026-02-24T02:32:39.800Z

Link: CVE-2026-27833

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-03T22:16:25.863

Modified: 2026-04-03T22:16:25.863

Link: CVE-2026-27833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses