SQL Injection Vulnerability in Piwigo Photo Gallery Application
CVE-2026-42323
7.2HIGH
What is CVE-2026-42323?
A vulnerability exists in the Piwigo photo gallery application, allowing an authenticated administrator to exploit insufficient numeric validation in the Batch Manager filter. The admin/batch_manager.php file processes user-supplied dimension and filesize values directly from the URL, which can lead to SQL injection. This flaw could enable an attacker to execute arbitrary SQL queries, potentially resulting in the disclosure, alteration, or disruption of database information. This vulnerability was addressed in Piwigo version 16.4.0.
Affected Version(s)
Piwigo < 16.4.0
