{"id":"CVE-2021-40678","details":"In Piwigo 11.5.0, there exists a persistent cross-site scripting in the single mode function through /admin.php?page=batch_manager&mode=unit.","modified":"2026-04-12T01:59:03.592262Z","published":"2022-06-14T13:15:07.937Z","references":[{"type":"REPORT","url":"https://github.com/Piwigo/Piwigo/issues/1476"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/piwigo/piwigo","events":[{"introduced":"0"},{"last_affected":"5075f97a46330dc72304695b2be3d90c3da3d18c"}],"database_specific":{"cpe":"cpe:2.3:a:piwigo:piwigo:11.5.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"11.5.0"}],"source":"CPE_FIELD"}}],"versions":["11.0.0","11.1.0","11.2.0","11.3.0","11.4.0","11.5.0","2.10.0RC1","2.10.0beta1","2.10.0beta2","2.11.0beta1","2.11.0beta2","2.11.0beta3","2.11.0beta4","2.8.0RC1","2.8.0RC2","2.9.0RC1","2.9.0RC2","2.9.0beta1","2.9.0beta2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-40678.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}