VendorsFacetag Projectfacetag0.0.3
Vulnerabilities

Facetag Project Facetag 0.0.3 for Piwigo 0.0.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2017-9426
ws.php in the Facetag extension 0.0.3 for Piwigo allows SQL injection via the imageId parameter in a facetag.changeTag or facetag.listTags action.
Published 2018-02-26 · Modified
9.8EPSS 0.027
CVE-2017-9425
The Facetag extension 0.0.3 for Piwigo allows XSS via the name parameter to ws.php in a facetag.changeTag action.
Published 2018-02-26 · Modified
6.1EPSS 0.014