← Back

CVE-2026-27834

nvd nist
Published: Apr 3, 2026Modified: Jul 24, 2026

JSON object

Loading...
7.2
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.2 / Impact: 5.9
Source: security-advisories@github.com (Secondary)

Description

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing authenticated administrators to execute arbitrary SQL commands. This issue has been patched in version 16.3.0.

Affected (1)

Products: Piwigo: Piwigo
1 product
Piwigo
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 16.3.0

References (4)

Source: security-advisories@github.com
ExploitMitigationVendor Advisory
Source: security-advisories@github.com
Release Notes
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitMitigationVendor Advisory

Timeline

No history available yet.