Description piwigo has XSS in password.php Remediation References CVE-2012-4525 Related Vulnerabilities WordPress Other Vulnerability (CVE-2006-6016) WordPress Plugin Thrive Themes Builder Security Bypass (2.2.3) Apache HTTP Server NULL Pointer Dereference Vulnerability (CVE-2017-3169) WordPress Plugin AccessPress Custom Post Type includes Backdoor [Only if downloaded via the vendor website] (1.0.8) WordPress Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2017-5488) Severity Medium Classification CVE-2012-4525 CWE-707 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Tags Missing Update Known Vulnerabilities