Vulnerability record · CVE-2025-62406 · published 18 November 2025
CVE-2025-62406: Piwigo weak password recovery vulnerability
Piwigo · Piwigo
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset URL by entering an existing username or email address. However, the hostname used to construct this URL is taken from the HTTP request's Host header and is not validated at all. Therefore, an attacker can send a password-reset URL with a modified hostname to an existing user whose username or email the attacker knows or guesses. This issue has been patched in version 15.7.0.
Description
Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset function allows sending a password-reset URL by entering an existing username or email address. However, the hostname used to construct this URL is taken from the HTTP request's Host header and is not validated at all. Therefore, an attacker can send a password-reset URL with a modified hostname to an existing user whose username or email the attacker knows or guesses. This issue has been patched in version 15.7.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/Piwigo/Piwigo/commit/9d2565465efc3570963ff431b45cad21610f6692 | Patch |
| https://github.com/Piwigo/Piwigo/security/advisories/GHSA-9986-w7jf-33f6 | ExploitVendor Advisory |
| https://github.com/Piwigo/Piwigo/security/advisories/GHSA-9986-w7jf-33f6 | ExploitVendor Advisory |
Track CVE-2025-62406 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-62406), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.