CVE-2026-78187 | Piwigo 16.3.0 Public Authentication Page lang cross site scripting (GHSA-rr39-mf4j-6594)
A vulnerability was found in Piwigo 16.3.0. It has been declared as problematic. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting.
This vulnerability is listed as CVE-2026-78187. The attack may be performed from remote. In addition, an exploit is available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More