{"id":"CVE-2022-32297","details":"Piwigo v12.2.0 was discovered to contain SQL injection vulnerability via the Search function.","modified":"2026-08-12T03:51:08.907309404Z","published":"2022-07-14T19:04:39Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32297.json"},"references":[{"type":"WEB","url":"https://github.com/sth276/research/blob/main/piwigo_vul/Second-Order%20SQL%20Injection%20Vulnerabilities%20in%20Piwigo.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/32xxx/CVE-2022-32297.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-32297"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/piwigo/piwigo","events":[{"introduced":"0"},{"last_affected":"7c27f9624aa41385cbf5422d4b299afb33d1d643"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:piwigo:piwigo:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"12.2.0"}]}}],"versions":["12.2.0","12.1.0","12.0.0","12.0.0RC2","12.0.0RC1","12.0.0beta2","12.0.0beta1","2.11.0beta4","2.11.0beta3","2.11.0beta2","2.11.0beta1","2.10.0RC1","2.10.0beta2","2.10.0beta1","2.9.0RC2","2.9.0RC1","2.9.0beta2","2.9.0beta1","2.8.0RC2","2.8.0RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-32297.json"}}],"schema_version":"1.9.0"}