CVE-2017-10682: Piwigo

Critical severity, CVSS 9.8. EPSS: 8.3% chance of exploitation in the next 30 days.

SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.

Affected products

  • Piwigo Piwigo: up to and including 2.9.1

Published 2017-06-29. Last modified 2026-06-17.