ProjectDiscovery received new Nuclei template submissions for two user-enumeration issues: CVE-2025-62512 in Piwigo and CVE-2025-59716 in ownCloud Guests. The Piwigo template targets a password-reset information leak tied to CWE-204, where observable differences in responses can reveal whether an account exists. Automated review marked the template as medium severity and said it had been validated against both vulnerable and patched targets, but warned that its current matcher logic is too generic and should include Piwigo-specific indicators such as a Piwigo string or the pwg_ cookie prefix to reduce false positives.
A separate review of the ownCloud Guests template found more serious detection problems. The bot said the template matched the message "No such guest user" for a random nonexistent email, behavior seen on both vulnerable and patched systems, meaning it would not reliably confirm enumeration and could produce false positives. Review guidance said a valid check would need version-based detection or multi-request behavioral testing that compares responses for valid pending guest emails against invalid ones; otherwise, the template should be documented as endpoint detection requiring manual validation. Both pull requests were submitted by DhiyaneshGeek and routed for human review by Akokonunes.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
On 2026-03-25, automated review concluded the ownCloud template was flawed because it matched behavior present on both vulnerable and patched systems. The review said proper verification would require comparing responses for valid pending guest emails versus invalid ones, or using version-based/manual validation approaches.
On 2026-03-25, a pull request proposed a Nuclei template for detecting the ownCloud Guests user enumeration issue. The pull request remained open and was sent for human review.
On 2026-03-24, automated review assessed the Piwigo template as medium severity and warned that its matcher logic was too generic, risking false positives. The review recommended adding Piwigo-specific identifiers such as a Piwigo string or pwg_ cookie prefix.
On 2026-03-24, a pull request added a Nuclei template to detect Piwigo user enumeration via password reset. The submission stated the template had been validated against both vulnerable and patched targets, and a human review was requested.
A user enumeration vulnerability in Piwigo's password reset functionality was identified and assigned CVE-2025-62512. The issue is associated with observable response discrepancies consistent with CWE-204.
A user enumeration vulnerability affecting ownCloud Guests was identified and assigned CVE-2025-59716. The issue involves distinguishing valid pending guest emails from invalid ones through behavioral differences in responses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.