PT-2026-28100 · Piwigo · Piwigo
Q1Uf3Ng
·
Published
2026-03-25
·
Updated
2026-04-03
·
CVE-2026-27634
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f min date available, f max date available, f min date created, f max date created) in ws std image sql filter() are concatenated directly into SQL without any escaping or type validation. This could result in an unauthenticated attacker reading the full database, including user password hashes. This issue has been patched in version 16.3.0.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Piwigo