Observable Response Discrepancy in Piwigo - CVE-2025-62512
Published: April 25, 2026 / Updated: April 26, 2026
Piwigo
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose valid usernames or email addresses.
The vulnerability exists due to observable response discrepancy in the password reset endpoint when handling password reset requests. A remote attacker can send a specially crafted request with a username or email address to disclose valid usernames or email addresses.
The endpoint returns distinct messages for existing and non-existent accounts.