CVE-2026-96673
Photoview through 2.4.0 SQL Injection via album download route
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.
| CWE | CWE-89 |
| Vendor | photoview |
| Product | photoview |
| Published | Sep 23, 2026 |
| Last Updated | Sep 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for photoview photoview
Be the first to know when new high vulnerabilities affecting photoview photoview are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Affected Versions
Photoview / Photoview
0 โค 2.4.0
References
github.com: https://github.com/photoview/photoview/pull/1453 github.com: https://github.com/photoview/photoview/commit/deb1b216e047a30803dc0f48a9fc3d4c4abda594 github.com: https://github.com/photoview/photoview/blob/v2.4.0/api/routes/downloads.go#L19-L29 hackmd.io: https://hackmd.io/@leediay/sqli-in-download-photoview github.com: https://github.com/photoview/photoview vulncheck.com: https://www.vulncheck.com/advisories/photoview-through-2.4.0-sql-injection-via-album-download-route
Credits
fedek-xbow ๐ leediay153