← Back to search

CVE-2026-62262

9.1 CRITICALpublic exploit available

Published 2026-09-25 · Updated 2026-09-29

AI risk analysis

Summary
This vulnerability allows unauthenticated users to extract database information through SQL injection by manipulating the ratings parameter in the search functionality.
Exploitability
Exploitation is relatively easy as it requires only crafting a specific ratings value and opening the returned URL. Precondition is that rating functionality is enabled.
Blast radius
If exploited, this could lead to full database compromise, including sensitive data exposure.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the rating functionality or apply a patch if available. No fixed version is mentioned, so disable the feature if unable to patch.
sql-injectionwebrceunauthpiwigo

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the unvalidated value in the search rules, and include/functions_search.inc.php integer-casts only the lower rating bound while concatenating the raw value as the SQL upper bound. This allows error-based or blind extraction of database information and database-dependent time delays through the public search flow. No fixed version is available as of this review.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-89

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.