CVE-2017-10682: Piwigo
Critical severity, CVSS 9.8. EPSS: 8.3% chance of exploitation in the next 30 days.
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.
Affected products
- Piwigo Piwigo: up to and including 2.9.1
Published 2017-06-29. Last modified 2026-06-17.