PT-2026-28100 · Piwigo · Piwigo

Q1Uf3Ng

·

Published

2026-03-25

·

Updated

2026-04-03

·

CVE-2026-27634

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f min date available, f max date available, f min date created, f max date created) in ws std image sql filter() are concatenated directly into SQL without any escaping or type validation. This could result in an unauthenticated attacker reading the full database, including user password hashes. This issue has been patched in version 16.3.0.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-27634

Affected Products

Piwigo