Should I use Piwigo?
Open Source Photo Library and DAM Software - piwigo.org
Depends. Buy it if you can self-host and patch promptly — it's a proven, free, multi-user photo gallery trusted by councils and utilities. Skip it if you want zero-maintenance consumer backup or AI search; Immich or PhotoPrism fit better.
Confidence
Medium. Based on 25+ public sources: reviews, Reddit threads, official case studies, pricing pages, and CVE databases.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support qualityNo support evidence in sources
- Security posture
Pricing
Free
Open Source (self-hosted)
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Hosted cloud plansPaid, 5 tiers
Best for
- →Self-hosters wanting a dependable gallery
- →Photographers sharing client galleries
- →Orgs needing a shared brand-asset library (DAM)
- →Multi-user teams controlling photo access
Not for
- ×Casual users wanting Google Photos-style auto-backup
- ×Anyone unwilling to patch security updates quickly
- ×Non-technical buyers expecting budget turnkey hosting
- ×Users wanting AI-heavy search — PhotoPrism or Immich fit better
Gotchas - check before you buy
high
Multiple 2025–2026 CVEs (SQLi, file read, RCE); patch to 16.4.0+ immediately
medium
Users question hosted pricing value versus the free self-hosted edition
medium
Steeper setup curve than Immich or Lychee; budget time for configuration
Pros and cons
Pros
- +Free, open-source core; G2 reviewers call it easy to use
- +Self-hosted community favorite: 'Piwigo does what you ask'
- +Proven at scale: utilities, county councils, universities run it
- +Large plugin ecosystem: video, watermarks, AI tagging
- +iOS and Android apps for uploads and browsing
Cons
- −More settings and configuration than Lychee or PhotoPrism
- −Recurring security holes: SQL injection, file read, RCE advisories
- −Some users say hosted plans only make sense if self-hosting
- −Self-hosting requires server, PHP, and database maintenance
- −Tiny team; free-tier support is community forums
Sources & method
Analyzed 10/02/2026 - 10 sources - Active risk: several 2025–2026 CVEs including SQL injection and arbitrary file read/RCE, fixed in v16.4.0 — patching discipline required.
official x3review x4security x3
- SQL injection (CVE-2026-27634, CVE-2026-27834), Two SQL injection vulnerabilities disclosed April 2026.
- Arbitrary file read (CVE-2026-85750), Affects Piwigo before v16.4.0.
- File read and RCE via format confusion, July 2026 advisory describing arbitrary file read and RCE.
- Information disclosure (CVE-2025-62512), Information disclosure flaw disclosed May 2026.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.