CVE-2026-78187: Cross Site Scripting in Piwigo
Description
CVE-2026-78187 is a cross-site scripting (XSS) vulnerability in Piwigo version 16.3.0 affecting the Public Authentication Page component via manipulation of the 'lang' argument. The vulnerability can be exploited remotely but requires high attack complexity and user interaction. Exploit code has been publicly disclosed. Upgrading to Piwigo version 16.4.0 addresses this issue.
CVSS v4.0
Score 2.3low
Affected software
Piwigo
cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Piwigo 16.3.0 involves improper sanitization of the 'lang' argument in the Public Authentication Page, allowing an attacker to perform cross-site scripting (XSS). The attack vector is remote, with high complexity and requires user interaction. The vulnerability has a low CVSS score of 2.3, reflecting limited impact and exploit difficulty. A patch identified by commit 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e is available in version 16.4.0.
Potential Impact
Successful exploitation could allow an attacker to execute arbitrary scripts in the context of the affected user's browser, potentially leading to session hijacking or other client-side impacts. However, the low CVSS score and high attack complexity indicate limited risk. No privilege escalation or server-side impact is indicated.
Mitigation Recommendations
Upgrade Piwigo to version 16.4.0, which contains the official fix for this vulnerability. No additional mitigation steps are required as the patch fully addresses the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-23T16:57:37.940Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a8bce18acd9273b49f5b7cd
Added to database: 08/24/2026, 04:52:40 UTC
Last enriched: 09/10/2026, 23:02:37 UTC
Last updated: 10/08/2026, 06:48:19 UTC
Views: 77
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.