Severity Critical High Medium Low Informational Vulnerability Categories Abuse Of Functionality Acumonitor Api Bfla Api Bola Api Broken Auth Api Broken Object Prop Auth Api Dos Api Improper Inventory Management Api Misconfiguration Api Ssrf Arbitrary File Creation Arbitrary File Read Authentication Bypass BOLA Bruteforce Possible Buffer Overflow CSRF CSTI Code Execution Configuration Crlf Injection Deepscan Default Credentials Denial Of Service Dev Files Directory Listing Directory Traversal Eli Injection Error Handling File Inclusion Http Parameter Pollution Http Response Splitting Information Disclosure Insecure Admin Access Insecure Deserialization Internal Ip Disclosure Known Vulnerabilities LLM Ldap Injection Llm Excessive Agency Llm Insecure Output Handling Llm Prompt Injection Llm Prompt Leakage Llm Sensitive Information Disclosure Malware Missing Update Privilege Escalation SSRF Sensitive Data Not Over Ssl Server Side Template Injection Session Fixation Source Code Disclosure Sql Injection Test Files Unauthenticated File Upload Url Redirection Weak Credentials Weak Crypto XFS XSS XXE Xpath Injection Vulnerability Name CVE CWE CWE Severity Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-48007) CVE-2022-48007 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2023-51790) CVE-2023-51790 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-28662) CVE-2024-28662 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-46333) CVE-2024-46333 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-46605) CVE-2024-46605 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-46606) CVE-2024-46606 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2024-52701) CVE-2024-52701 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) Vulnerability (CVE-2023-44393) CVE-2023-44393 CWE-707 CWE-707 Medium Piwigo Improper Neutralization of Special Elements used in a Command ('Command Injection') Vulnerability (CVE-2021-40553) CVE-2021-40553 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2933) CVE-2009-2933 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-4649) CVE-2014-4649 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2014-9115) CVE-2014-9115 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-1441) CVE-2015-1441 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-1517) CVE-2015-1517 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-2035) CVE-2015-2035 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-9463) CVE-2017-9463 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-10682) CVE-2017-10682 CWE-138 CWE-138 Critical Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-16893) CVE-2017-16893 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-17822) CVE-2017-17822 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-17823) CVE-2017-17823 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2017-17824) CVE-2017-17824 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2018-6883) CVE-2018-6883 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19212) CVE-2020-19212 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19213) CVE-2020-19213 CWE-138 CWE-138 Critical Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19215) CVE-2020-19215 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19216) CVE-2020-19216 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2020-19217) CVE-2020-19217 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-27973) CVE-2021-27973 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-32615) CVE-2021-32615 CWE-138 CWE-138 Critical Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-40313) CVE-2021-40313 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2021-40317) CVE-2021-40317 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-26266) CVE-2022-26266 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2022-32297) CVE-2022-32297 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-26876) CVE-2023-26876 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-27233) CVE-2023-27233 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33361) CVE-2023-33361 CWE-138 CWE-138 Critical Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-33362) CVE-2023-33362 CWE-138 CWE-138 Critical Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-34626) CVE-2023-34626 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-37270) CVE-2023-37270 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2024-43018) CVE-2024-43018 CWE-138 CWE-138 Medium Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2026-27634) CVE-2026-27634 CWE-138 CWE-138 Critical Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2026-27834) CVE-2026-27834 CWE-138 CWE-138 High Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2026-27885) CVE-2026-27885 CWE-138 CWE-138 High Piwigo Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG) Vulnerability (CVE-2016-3735) CVE-2016-3735 CWE-335 CWE-335 High Piwigo Missing Authorization Vulnerability (CVE-2026-27833) CVE-2026-27833 CWE-862 CWE-862 High Piwigo Observable Response Discrepancy Vulnerability (CVE-2025-62512) CVE-2025-62512 CWE-204 CWE-204 Medium Piwigo URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-9464) CVE-2017-9464 CWE-601 CWE-601 Medium Piwigo Use of Insufficiently Random Values Vulnerability (CVE-2024-48928) CVE-2024-48928 CWE-330 CWE-330 High Piwigo Weak Password Recovery Mechanism for Forgotten Password Vulnerability (CVE-2025-62406) CVE-2025-62406 CWE-640 CWE-640 High Play Framework Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2020-12480) CVE-2020-12480 CWE-352 CWE-352 Medium Play Framework Data Amplification Vulnerability (CVE-2020-28923) CVE-2020-28923 Low Play Framework Generation of Error Message Containing Sensitive Information Vulnerability (CVE-2022-31023) CVE-2022-31023 CWE-209 CWE-209 High Play Framework Improper Input Validation Vulnerability (CVE-2015-2156) CVE-2015-2156 CWE-20 CWE-20 High Play Framework Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2018-13864) CVE-2018-13864 CWE-22 CWE-22 High Play Framework Improper Restriction of XML External Entity Reference Vulnerability (CVE-2014-3630) CVE-2014-3630 CWE-611 CWE-611 Critical Play Framework Inadequate Encryption Strength Vulnerability (CVE-2019-17598) CVE-2019-17598 CWE-326 CWE-326 High Play Framework Out-of-bounds Write Vulnerability (CVE-2020-27196) CVE-2020-27196 CWE-787 CWE-787 High Play Framework Uncontrolled Recursion Vulnerability (CVE-2020-26882) CVE-2020-26882 CWE-674 CWE-674 High Play Framework Uncontrolled Recursion Vulnerability (CVE-2020-26883) CVE-2020-26883 CWE-674 CWE-674 High Play Framework Uncontrolled Resource Consumption Vulnerability (CVE-2022-31018) CVE-2022-31018 CWE-400 CWE-400 High Play framework weak secret key CWE-693 CWE-693 Medium PleskLin Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-43784) CVE-2023-43784 CWE-668 CWE-668 High PleskLin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-0132) CVE-2013-0132 CWE-94 CWE-94 Medium PleskLin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-18793) CVE-2019-18793 CWE-707 CWE-707 Medium PleskLin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11583) CVE-2020-11583 CWE-707 CWE-707 Medium PleskLin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11584) CVE-2020-11584 CWE-707 CWE-707 Medium PleskLin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2021-35976) CVE-2021-35976 CWE-707 CWE-707 Medium PleskLin Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2012-1557) CVE-2012-1557 CWE-138 CWE-138 High PleskLin Other Vulnerability (CVE-2013-0133) CVE-2013-0133 High PleskLin Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4878) CVE-2013-4878 CWE-264 CWE-264 High PleskLin URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-24044) CVE-2023-24044 CWE-601 CWE-601 Medium PleskWin Exposure of Resource to Wrong Sphere Vulnerability (CVE-2023-43784) CVE-2023-43784 CWE-668 CWE-668 High PleskWin Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-0132) CVE-2013-0132 CWE-94 CWE-94 Medium PleskWin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2019-18793) CVE-2019-18793 CWE-707 CWE-707 Medium PleskWin Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11583) CVE-2020-11583 CWE-707 CWE-707 Medium 1...164165166167...327 165 / 327