No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 28 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 26 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Piwigo
Piwigo piwigo |
|
| Vendors & Products |
Piwigo
Piwigo piwigo |
Fri, 25 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php accepts administrator-controlled dimension width, height, and ratio values and filesize values from the Batch Manager filter URL without numeric validation. The URL filter parser stores those values in the bulk_manager_filter session state, and later query construction concatenates them into SQL predicates, unlike the validated POST filter path. An authenticated administrator can use crafted filter values to execute time-based or other SQL expressions and potentially disclose, modify, or disrupt database data. This issue is fixed in version 16.4.0. | |
| Title | Piwigo: SQL Injection in Batch Manager | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-28T14:29:29.756Z
Reserved: 2026-04-26T12:37:18.170Z
Link: CVE-2026-42323
Updated: 2026-09-28T14:29:04.327Z
Status : Deferred
Published: 2026-09-25T16:17:25.607
Modified: 2026-09-28T15:17:17.250
Link: CVE-2026-42323
No data.
OpenCVE Enrichment
Updated: 2026-09-26T13:00:14Z