CVE-2014-4649: Piwigo

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in the photo-edit subsystem in Piwigo 2.6.x and 2.7.x before 2.7.0beta2 allows remote authenticated administrators to execute arbitrary SQL commands via the associate[] field.

Affected products

  • Piwigo Piwigo: version 2.6.0 only; version 2.6.1 only; version 2.6.2 only; version 2.6.3 only; version 2.7.0 only

Published 2014-06-28. Last modified 2026-06-17.