Piwigo 是一款功能完整的开源 Web 相册应用程序。在 16.4.0 版本之前,admin/element_set_ranks.php 在未强制执行现有排序字段白名单的情况下,存储了由管理员控制的 image_order[] 值。随后,admin/batch_manager_global.php、admin/batch_manager_unit.php、include/section_init.inc.php 和 include/ws_functions/pwg.categories.php 等脚本会将存储的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42322 | 9.1 CRITICAL | Piwigo: Authenticated RCE via File Upload in Logo Upload Feature |
| CVE-2026-62262 | 9.1 CRITICAL | Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` |
| CVE-2026-44642 | 8.1 HIGH | Piwigo: SQL injection in upgrade authentication allows unauthenticated upgrade authorizati |
| CVE-2026-42323 | 7.2 HIGH | Piwigo: SQL Injection in Batch Manager |
| CVE-2026-85750 | 7.2 HIGH | Piwigo arbitrary file read and remote code execution via insecure image processing |
No comments yet