Executive brief
Piwigo is an open-source photo gallery application used to manage and display image collections on the web. A security flaw allows unauthenticated attackers to bypass security controls and interact directly with the application's database. This could lead to the theft of sensitive information, including user account details and password hashes, potentially compromising the entire installation.
Technical details
An unauthenticated SQL injection vulnerability exists in Piwigo's ws_std_image_sql_filter() function due to improper neutralization of the f_min_date_available, f_max_date_available, f_min_date_created, and f_max_date_created parameters. These inputs are concatenated directly into SQL queries without escaping or type validation. The vulnerability is reachable via guest-accessible API methods such as pwg.categories.getImages and pwg.tags.getImages when guest access is enabled (the default configuration). Attackers can utilize time-based or error-based techniques to extract sensitive data, including the full database content and user password hashes. The issue is resolved in version 16.3.0 by implementing strict date format validation.
Affected products
- Piwigo Piwigo < 16.3.0
Timeline
- 2026-02-24: patched: Version 16.3.0 released
- 2026-04-01: advisory: GitHub Security Advisory published
- 2026-04-03: disclosed: CVE published to NVD