CVE 8.7 HIGH

Piwigo: Pre-auth SQL injection via date filter parameters in ws_std_image_sql_filter_CVE-2026-27634

8.7 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Description

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, the four date filter parameters (f_min_date_available, f_max_date_available, f_min_date_created, f_max_date_created) in ws_std_image_sql_filter() are concatenated directly into SQL without any escaping or type validation. This could result in an unauthenticated attacker reading the full database, including user password hashes. This issue has been patched in version 16.3.0.

Basic Information

ID CVE-2026-27634
Source GitHub_M
Published Apr 3, 2026 at 21:33
Modified Apr 6, 2026 at 13:13

Affected Product

Vendor Piwigo
Product Piwigo
Version < 16.3.0
Affected Versions Piwigo Piwigo < 16.3.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.