๐Ÿ” CVE Alert

CVE-2026-62262

CRITICAL 9.1

Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
0th

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the unvalidated value in the search rules, and include/functions_search.inc.php integer-casts only the lower rating bound while concatenating the raw value as the SQL upper bound. This allows error-based or blind extraction of database information and database-dependent time delays through the public search flow. No fixed version is available as of this review.

CWE CWE-89
Vendor piwigo
Product piwigo
Published Sep 25, 2026
Stay Ahead of the Next One

Get instant alerts for piwigo piwigo

Be the first to know when new critical vulnerabilities affecting piwigo piwigo are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Piwigo / Piwigo
< 17.0.0beta1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Piwigo/Piwigo/security/advisories/GHSA-hq29-8hhx-5jwc github.com: https://github.com/Piwigo/Piwigo/commit/9755d88edf38b94bafdedb0b3aba7304a94e2e5c github.com: https://github.com/Piwigo/Piwigo/commit/aede490a0b3a6c246f1f4689ca86c8fee377a7ae