Total vulnerabilities in the database
admin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is exploitable via CSRF.
Software | From | Fixed in |
---|---|---|
piwigo / piwigo | 2.9.5 | 2.9.5.x |