CVE-2026-78187

Piwigo Public Authentication cross site scripting

A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 16.4.0 will fix this issue. The name of the patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e. It is recommended to upgrade the affected component.


We have discovered 212 live websites that are affected by CVE-2026-78187.

Run a Free Instant Scan




Affected Software

Product  Piwigo
Category Photo Galleries
Vulnerable Domains212 live websites (9.13% of Piwigo install base)
Vulnerable Versions
  • from 16.3 through 16.3
Vulnerable Versions Count1 versions ( 2.78% of all versions)



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • Leousum (VulDB User) (reporter)

Website Distribution by Country

Number of websites using CVE-2026-78187
United States44 websites



France46 websites
Germany44 websites
Switzerland11 websites
Austria10 websites
GB8 websites
Netherlands8 websites
Poland7 websites
Czech Republic6 websites
Italy5 websites

Website Distribution by TLD

Number of websites using CVE-2026-78187
.com55 websites
.de29 websites
.org18 websites
.fr16 websites
.net16 websites
.at9 websites
.nl9 websites
.ch9 websites
.eu7 websites
.be4 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-78187

Top websites that are affected by CVE-2026-78187. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********************.at Germany*,***,***
*********.**.uk GB*,***,***
*********.com United States*,***,***
************.**.uk GB*,***,***
******.******.com France*,***,***
*******************.de Germany*,***,***
*******.com United States*,***,***
******.******.com France*,***,***
*************************.******.com France*,***,***
************.com United States*,***,***
See full domain list

FAQ

A total of 212 websites have been identified as vulnerable to CVE-2026-78187, based on global website indexing conducted by WebTechSurvey.
The Piwigo is affected by the CVE-2026-78187 vulnerability.
Piwigo versions up to and including 16.3 are vulnerable to CVE-2026-78187.