CVE-2026-42324 | Piwigo up to 16.3.x Image Order element_set_ranks.php image_order[] sql injection

SecurityVulns

A vulnerability marked as problematic has been reported in Piwigo up to 16.3.x. This issue affects some unknown processing of the file admin/element_set_ranks.php of the component Image Order. Performing a manipulation of the argument image_order[] results in sql injection.

This vulnerability is reported as CVE-2026-42324. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More