References https://nvd.nist.gov/vuln/detail/CVE-2026-27833 https://www.sentinelone.com/vulnerability-database/cve-2026-27833/ https://github.com/Piwigo/Piwigo/security/advisories/GHSA-397m-gfhm-pmg2 https://pentest-tools.com/vulnerabilities-exploits/piwigo-1630-unauthenticated-information-disclosure-via-history-api_29395 https://www.incibe.es/index.php/en/incibe-cert/early-warning/vulnerabilities/cve-2026-27833 https://app.opencve.io/cve/CVE-2026-27833 https://www.thehackerwire.com/vulnerability/CVE-2026-27833/
Related VulnerabilitiesPoCflowise-chatflows-exposure: Flowise AI - Unauthenticated Chatflows API ExposurePoCCVE-2026-9133: Amazon rabbitmq-aws 0.1.0 through 0.2.0 - Arbitrary File Read鎧應科技|CAYIN CMS-WS/CMS-SE - Missing Authentication鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload網韻資訊|NewSiteServer (NSS) 新式校園網站系統 - Missing Authentication網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-16268: Newsletters < 4.16 - Unauthenticated SSRF via SNS Bounce HandlerPoCCVE-2026-10768: Drupal LocalGov Workflows < 1.6.0 - Information DisclosurePoCCVE-2026-58644: Microsoft SharePoint Server - WS-Federation BinaryFormatter Deserialization RCEKestra /api/v1/main/flows/configs 命令执行漏洞(CVE-2026-53576)Flowise /api/v1/chatflows 文件上传漏洞(CVE-2025-71334)PoC方正畅享全媒体采编系统 /newsedit/msg/cc.do 信息泄露漏洞Hoverfly /api/v2/ws/logs 信息泄露漏洞