CVE-2023-26876: Piwigo
High severity, CVSS 8.8. EPSS: 9.7% chance of exploitation in the next 30 days.
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
Affected products
- Piwigo Piwigo: up to and including 13.5.0
Published 2023-04-21. Last modified 2026-06-17.