Piwigo 是一款功能完整的开源 Web 照片画廊应用程序。在 16.4.0 版本之前,admin/include/functions_upgrade.php 中的 check_upgrade_access_rights() 函数仅在已移除 get_magic_quotes_gpc 函数的条件下对提交的用户名进行转义处理。因此,在 PHP 8 及更高版本中,未经身份验证的用户名会被直接拼接到升级认证 SQL 查询语句中。当存在待处理的数据库升级任务时,构造的查询结果可以满足状态和密码检查,并设置 PHPWG_IN
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-42322 | 9.1 CRITICAL | Piwigo: Authenticated RCE via File Upload in Logo Upload Feature |
| CVE-2026-62262 | 9.1 CRITICAL | Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create` |
| CVE-2026-42324 | 7.2 HIGH | Piwigo: Second-Order SQL Injection |
| CVE-2026-42323 | 7.2 HIGH | Piwigo: SQL Injection in Batch Manager |
| CVE-2026-85750 | 7.2 HIGH | Piwigo arbitrary file read and remote code execution via insecure image processing |
No comments yet