PT-2026-98878 · Piwigo · Piwigo

CVE-2026-42323

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Piwigo versions prior to 16.4.0
Description The application fails to perform numeric validation on dimension width, height, ratio, and filesize values provided via the Batch Manager filter URL in the 'admin/batch manager.php' endpoint. These values are stored in the bulk manager filter session state and subsequently concatenated into SQL predicates during query construction. An authenticated administrator can exploit this by using crafted filter values to execute time-based or other SQL expressions, which may lead to the disclosure, modification, or disruption of database data.
Recommendations Update to version 16.4.0.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42323
GHSA-7R67-9XHQ-7P2C

Affected Products

Piwigo