CVE-2026-27834

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability exists in the pwg.users.getList Web Service API method. The filter parameter is directly concatenated into a SQL query without proper sanitization, allowing authenticated administrators to execute arbitrary SQL commands. This issue has been patched in version 16.3.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*

History

24 Jul 2026, 22:10

Type Values Removed Values Added
Summary
  • (es) Piwigo es una aplicación de galería de fotos de código abierto para la web. Antes de la versión 16.3.0, existe una vulnerabilidad de inyección SQL en el método API de servicio web pwg.users.getList. El parámetro filter se concatena directamente en una consulta SQL sin una sanitización adecuada, permitiendo a los administradores autenticados ejecutar comandos SQL arbitrarios. Este problema ha sido parcheado en la versión 16.3.0.

09 Apr 2026, 21:15

Type Values Removed Values Added
References () https://github.com/Piwigo/Piwigo/commit/9df471f16243371dc3725c5262e1632d23c8218a - () https://github.com/Piwigo/Piwigo/commit/9df471f16243371dc3725c5262e1632d23c8218a - Patch
References () https://github.com/Piwigo/Piwigo/security/advisories/GHSA-5jwg-cr5q-vjq2 - () https://github.com/Piwigo/Piwigo/security/advisories/GHSA-5jwg-cr5q-vjq2 - Exploit, Mitigation, Vendor Advisory
References () https://piwigo.org/release-16.3.0 - () https://piwigo.org/release-16.3.0 - Release Notes
CPE cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*
First Time Piwigo
Piwigo piwigo

06 Apr 2026, 16:16

Type Values Removed Values Added
References () https://github.com/Piwigo/Piwigo/security/advisories/GHSA-5jwg-cr5q-vjq2 - () https://github.com/Piwigo/Piwigo/security/advisories/GHSA-5jwg-cr5q-vjq2 -

03 Apr 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 22:16

Updated : 2026-07-24 22:10


NVD link : CVE-2026-27834

Mitre link : CVE-2026-27834

CVE.ORG link : CVE-2026-27834


JSON object : View

Products Affected

piwigo

  • piwigo
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')