๐Ÿ” CVE Alert

CVE-2026-42324

HIGH 7.2

Piwigo: Second-Order SQL Injection

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The stored album image_order expression is later concatenated into ORDER BY clauses by admin/batch_manager_global.php, admin/batch_manager_unit.php, include/section_init.inc.php, and include/ws_functions/pwg.categories.php. When at least one album contains at least one photo, an authenticated administrator can store a crafted expression and trigger it in a later album or Batch Manager query to disclose, modify, or disrupt database data. This issue is fixed in version 16.4.0.

CWE CWE-89
Vendor piwigo
Product piwigo
Published Sep 25, 2026
Last Updated Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for piwigo piwigo

Be the first to know when new high vulnerabilities affecting piwigo piwigo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Piwigo / Piwigo
< 16.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Piwigo/Piwigo/security/advisories/GHSA-jhp4-7f82-8f6q github.com: https://github.com/Piwigo/Piwigo/commit/ba1f803f8cefd3602ccb9c6f0155cd529510288a github.com: https://github.com/Piwigo/Piwigo/commit/ef9e65386d76f9c85f1e23a45dd7af14a5b73a47 github.com: https://github.com/Piwigo/Piwigo/releases/tag/16.4.0