CVE-2025-62512General(piwigo / piwigo)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows an unauthenticated attacker to determine whether a given username or email address exists in the system. The endpoint at password.php?action=lost returns distinct messages for valid vs. invalid accounts, enabling user enumeration. As of time of publication, no known patches are available.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-204

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • piwigo

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-24); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
piwigo

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-24: 1Mentions · 2026-02-25: 1Mentions · 2026-03-25: 1PoC Mentioned / Linked · 2026-03-25: 1Technical Details · 2026-02-24: 1Technical Details · 2026-03-25: 102-2402-2503-25
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-241
General1
2026-02-251
General1
2026-03-251
Disclosure1
Full discourse3 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2025-62512 - medium 🚨 Piwigo - User Enumeration via Password Reset > Piwigo is an open source photo gallery application for the web. In version 15.5.0 and... 👾 https://cloud.projectdiscovery.io/library/CVE-2025-62512 @pdnuclei #NucleiTemplates #cve

    Post summary

    A medium‑severity vulnerability (CVE‑2025‑62512) in Piwigo allows user enumeration through the password reset feature in version 15.5.0, with a Project Discovery link provided for additional details.

    01010218
    904 followersView on X
  • CVE@CVEnew
    General

    CVE-2025-62512 Piwigo is an open source photo gallery application for the web. In version 15.5.0 and likely earlier 15.x releases, the password reset functionality in Piwigo allows … https://www.cve.org/CVERecord?id=CVE-2025-62512

    Post summary

    The text references CVE-2025-62512 in Piwigo, noting a potential issue with password reset functionality, but provides no further details or actionable information.

    00000135
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-62512 Unauthenticated User Enumeration Vulnerability in Piwigo 15.5.0 Password Reset https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-62512

    Post summary

    The text references CVE-2025-62512, describing an unauthenticated user enumeration flaw in Piwigo 15.5.0’s password reset functionality, but provides no evidence of PoC, exploit, or patch.

    0000041
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppiwigopiwigo---

Explore more