๐Ÿ” CVE Alert

CVE-2026-96673

HIGH 7.5

Photoview through 2.4.0 SQL Injection via album download route

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.

CWE CWE-89
Vendor photoview
Product photoview
Published Sep 23, 2026
Last Updated Sep 23, 2026
Stay Ahead of the Next One

Get instant alerts for photoview photoview

Be the first to know when new high vulnerabilities affecting photoview photoview are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Photoview / Photoview
0 โ‰ค 2.4.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/photoview/photoview/pull/1453 github.com: https://github.com/photoview/photoview/commit/deb1b216e047a30803dc0f48a9fc3d4c4abda594 github.com: https://github.com/photoview/photoview/blob/v2.4.0/api/routes/downloads.go#L19-L29 hackmd.io: https://hackmd.io/@leediay/sqli-in-download-photoview github.com: https://github.com/photoview/photoview vulncheck.com: https://www.vulncheck.com/advisories/photoview-through-2.4.0-sql-injection-via-album-download-route

Credits

fedek-xbow ๐Ÿ” leediay153