These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-62262 is a critical vulnerability in Piwigo, a full-featured open-source photo gallery application for the web. The vulnerability affects Piwigo versions 17.0.0beta1 and earlier, where an unauthenticated guest can exploit the pwg.images.filteredSearch.create function to extract database information and cause database-dependent time delays through the public search flow. This is due to the imprope [truncated]
CVE-2026-44642 is a high-severity vulnerability in Piwigo, a full-featured open-source photo gallery application for the web. The vulnerability exists in the check_upgrade_access_rights() function in admin/include/functions_upgrade.php, where an unauthenticated username is concatenated directly into the upgrade authentication SQL query on PHP 8 and later. This allows unauthorized database integrity change [truncated]
CVE-2026-42324 is a high-severity vulnerability in Piwigo, a full-featured open-source photo gallery application for the web. An authenticated administrator can store a crafted expression in the image_order[] values without enforcing the existing sort-field whitelist, which can be triggered later to disclose, modify, or disrupt database data. The issue is fixed in version 16.4.0.
CVE-2026-42323 is a high-severity vulnerability in Piwigo, a full-featured open-source photo gallery application for the web. An authenticated administrator can exploit this issue to execute SQL expressions and potentially disclose, modify, or disrupt database data. The vulnerability is caused by the lack of numeric validation for administrator-controlled dimension width, height, and ratio values and file [truncated]
CVE-2026-42322 is a critical vulnerability in Piwigo, a full-featured open-source photo gallery application for the web. An authenticated administrator can upload image content with a server-executable final extension, causing the file to be placed in the web-accessible logo directory and executed when requested if the web server handles that extension. This can permit arbitrary command execution, data di [truncated]
CVE-2026-85750 Piwigo vulnerability debrief. Piwigo before v16.4.0 is vulnerable to arbitrary file read and remote code execution in image upload handling when using the Imagick library due to insufficient validation and unsafe processing of user-supplied image files. This vulnerability allows for potential unauthorized server-side file reads and writes, and possible remote code execution on affected Piwi [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T03:16:47.980Z and has not been modified since then. This medium severity vulnerability, CVE-2026-84441, affects Piwigo up to version 16.3.0, specifically in the image derivative handler component. The vulnerability class is path traversal, allowing attackers to manipulate file paths potentially l [truncated]
CVE-2026-35048 is a critical vulnerability in Piwigo versions 16.3.0 and earlier. The Piwigo installer accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed, allowing raw user input to be interpolated directly into PHP source code. An unauthenticated attacker can inject arb [truncated]
A SQL Injection vulnerability was discovered in Piwigo, affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including user credentials, email addresses, and all stored content. The issue has been patched in version 16.3.0. An executive overview of the vulnerability reveals that it has a high CVSS score of 7.2 and i [truncated]
CVE-2026-27834 is a SQL Injection vulnerability in Piwigo's pwg.users.getList Web Service API method. The vulnerability allows authenticated administrators to execute arbitrary SQL commands due to improper sanitization of the filter parameter. This issue was patched in version 16.3.0. Affected users should update to this version or apply necessary patches. The vulnerability has a high impact on systems wi [truncated]
CVE-2026-27833 is a high-severity vulnerability in Piwigo's pwg.history.search API method, allowing unauthenticated users to access full browsing history. This issue was patched in version 16.3.0. Affected users should prioritize updating to prevent unauthorized access to gallery visitor history. The CVE record was published on 2026-04-03T22:16:25.863Z and has not been modified since then. The NVD entry i [truncated]
CVE-2026-27634 is a high-severity vulnerability in Piwigo, an open-source photo gallery application. The vulnerability allows an unauthenticated attacker to read the full database, including user password hashes, by exploiting the ws_std_image_sql_filter() function. This function concatenates four date filter parameters directly into SQL without proper escaping or type validation. Users of Piwigo versions [truncated]
CVE-2017-5608 is a cross-site scripting (XSS) issue in Piwigo’s image upload flow. According to the CVE record, versions before 2.8.6 could allow a remote attacker to inject arbitrary web script or HTML through a crafted image filename. The vulnerability is publicly documented in NVD and tied to a vendor fix in Piwigo 2.8.6.