CVE-2026-44642: Piwigo

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_rights() in admin/include/functions_upgrade.php conditionally escapes the submitted username only when the removed get_magic_quotes_gpc function exists, so PHP 8 and later concatenate an unauthenticated username directly into the upgrade authentication SQL query. When database upgrades are pending, a crafted query result can satisfy the status and password checks, set PHPWG_IN_UPGRADE, and authorize upgrade execution without valid administrator credentials. This can cause unauthorized database integrity changes and service disruption. This vulnerability is fixed in 16.4.0.

Affected products

  • Piwigo Piwigo: before 16.4.0 (fixed in 16.4.0)

Published 2026-09-25. Last modified 2026-09-25.