CVE-2026-42324: Piwigo: Second-Order SQL Injection

Published Sep 25, 2026
·
Updated

Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/elementsetranks.php stores administrator-controlled imageorder[] values without enforcing the existing sort-field whitelist. The stored album imageorder expression is later concatenated into ORDER BY clauses by admin/batchmanagerglobal.php, admin/batchmanagerunit.php, include/sectioninit.inc.php, and include/wsfunctions/pwg.categories.php. When at least one album contains at least one photo, an authenticated administrator can store a crafted expression and trigger it in a later album or Batch Manager query to disclose, modify, or disrupt database data. This issue is fixed in version 16.4.0.

Affected Software

1 affected component
Piwigo piwigo<16.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Piwigo to a version that resolves this vulnerability.

    Fixed in 16.4.0

Event History

Sep 25, 2026
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated Piwigo administrator can exploit it. Exploitation also requires that at least one album contains at least one photo.

2

What does an attacker need to do to trigger the injection?

The attacker must store a crafted value in an album's image_order[] setting through admin/element_set_ranks.php. The stored expression is triggered later when it is used in an album or Batch Manager query.

3

Are installations affected by default?

The issue is reachable through administrator-controlled image ordering values, so an attacker needs administrative access rather than unauthenticated access. Affected deployments are those running versions prior to 16.4.0 with an album containing at least one photo.

4

What is the remediation?

Upgrade Piwigo to version 16.4.0, which fixes the issue. If upgrading cannot happen immediately, restrict administrator access to trusted users and avoid setting untrusted image ordering values.

5

How can I determine whether a system may be affected?

Check whether the Piwigo version is earlier than 16.4.0. Also review album image ordering configuration for unexpected or crafted image_order[] expressions, particularly where administrators have used ranking or ordering controls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203