CVE-2020-19216: Piwigo

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

SQL Injection vulnerability in admin/user_perm.php in piwigo v2.9.5, via the cat_false parameter to admin.php?page=group_perm.

Affected products

  • Piwigo Piwigo: version 2.9.5 only

Published 2022-05-06. Last modified 2026-06-17.