{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/piwigo--16.3.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-84441"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Piwigo (\u003c= 16.3.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Piwigo"],"content_html":"\u003cp\u003ePiwigo versions up to and including 16.3.0 are vulnerable to a path traversal flaw residing within the Image Derivative Handler component, specifically within the i.php file. This vulnerability arises from improper input validation, allowing a remote, unauthenticated attacker to supply specially crafted input to manipulate file paths. By exploiting this flaw, an attacker can bypass intended access controls to read sensitive files or potentially interact with arbitrary files located on the underlying server filesystem. Given that the exploit code has been publicly disclosed, the barrier to entry for exploitation is low, and organizations running affected Piwigo installations should prioritize mitigation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized file access on the host server. This can lead to the exposure of sensitive configuration files, database credentials, or application source code, potentially resulting in complete system compromise depending on the server configuration and file permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all Piwigo installations to version 16.3.1 or later immediately. Ensure that the web server process runs with the least privilege necessary to limit the impact of potential path traversal attacks.\u003c/p\u003e\n","date_modified":"2026-09-02T05:11:53Z","date_published":"2026-09-02T05:11:53Z","id":"https://feed.craftedsignal.io/briefs/2026-09-piwigo-path-traversal/","summary":"Piwigo versions up to 16.3.0 contain a path traversal vulnerability in the i.php component, allowing remote unauthenticated attackers to access unauthorized files on the host system.","title":"Path Traversal Vulnerability in Piwigo Image Derivative Handler","url":"https://feed.craftedsignal.io/briefs/2026-09-piwigo-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Piwigo (\u003c= 16.3.0)","version":"https://jsonfeed.org/version/1.1"}