•  » Requests
  •  » [resolved] XSS vulnerability in OSM-plugin

#1 2026-02-02 17:07:25

gmanic
Member
2026-02-02
3

[resolved] XSS vulnerability in OSM-plugin

Hello/Hi/Greetings,

there is a XSS-vulnerability in the osm-plugin. Its existence can easily be verified by calling this URI on a osm-enabled piwigo instance - at least at mine it showed the pop-up:

<your-piwigo-domain>/index.php?zoom=</script><script>confirm(1)</script>

Piwigo is latest 16.2 version with latest plugin version.

I have opened this github-issue for this (no response, so far):
[Github] piwigo-openstreetmap issue #283

Further, I have created a PR to fix this vulnerability:
https://github.com/Piwigo/piwigo-openstreetmap/pull/284

I would be glad, if this could be checked and then hopefully merged to make Piwigo a little safer place :)

Best
Jens

Offline

 

#2 2026-02-16 14:32:19

gmanic
Member
2026-02-02
3

Re: [resolved] XSS vulnerability in OSM-plugin

Unfortunately, no response here nor on github.com for the already provided PR.

So, this is a short *bump*

Offline

 

#3 2026-02-27 00:40:40

gmanic
Member
2026-02-02
3

Re: [resolved] XSS vulnerability in OSM-plugin

No one?

I mean, Piwigo got a new release, fixing security issues. Good.

But plugins - nobody cares??

Offline

 

#4 2026-03-02 14:41:39

hannah
Piwigo Team
2019-04-24
84

Re: [resolved] XSS vulnerability in OSM-plugin

Hi gmanic,

As I mentionned in the github issue, please don't think we ignore community participation. We take security issues very seriously.

We are very greatful for your participation, your PR has been merged and a new verison of the plugin published.

Thank you for your contribution to Piwigo

Offline

 
  •  » Requests
  •  » [resolved] XSS vulnerability in OSM-plugin

Board footer

Powered by FluxBB

github linkedin newsletter Piwigo.org © 2002-2026 · Contact