<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Piwigo (&lt;= 16.3.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/piwigo--16.3.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 02 Sep 2026 05:11:53 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/piwigo--16.3.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in Piwigo Image Derivative Handler</title><link>https://feed.craftedsignal.io/briefs/2026-09-piwigo-path-traversal/</link><pubDate>Wed, 02 Sep 2026 05:11:53 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-piwigo-path-traversal/</guid><description>Piwigo versions up to 16.3.0 contain a path traversal vulnerability in the i.php component, allowing remote unauthenticated attackers to access unauthorized files on the host system.</description><content:encoded><![CDATA[<p>Piwigo versions up to and including 16.3.0 are vulnerable to a path traversal flaw residing within the Image Derivative Handler component, specifically within the i.php file. This vulnerability arises from improper input validation, allowing a remote, unauthenticated attacker to supply specially crafted input to manipulate file paths. By exploiting this flaw, an attacker can bypass intended access controls to read sensitive files or potentially interact with arbitrary files located on the underlying server filesystem. Given that the exploit code has been publicly disclosed, the barrier to entry for exploitation is low, and organizations running affected Piwigo installations should prioritize mitigation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized file access on the host server. This can lead to the exposure of sensitive configuration files, database credentials, or application source code, potentially resulting in complete system compromise depending on the server configuration and file permissions.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all Piwigo installations to version 16.3.1 or later immediately. Ensure that the web server process runs with the least privilege necessary to limit the impact of potential path traversal attacks.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>