High severity8.8NVD Advisory· Published Apr 21, 2023· Updated Jun 17, 2026
CVE-2023-26876
CVE-2023-26876
Description
SQL injection vulnerability found in Piwigo v.13.5.0 and before allows a remote attacker to execute arbitrary code via the filter_user_id parameter to the admin.php?page=history&filter_image_id=&filter_user_id endpoint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- gist.github.com/rodnt/a190d14d1715890d8df19bad58b90693nvdExploitThird Party Advisory
- piwigo.comnvdProduct
- www.tempest.com.brnvdNot Applicable
- packetstormsecurity.com/files/172059/Piwigo-13.5.0-SQL-Injection.htmlnvd
- seclists.org/fulldisclosure/2023/Apr/13nvd
News mentions
0No linked articles in our index yet.