{"id":"CVE-2026-42324","summary":"Piwigo: Second-Order SQL Injection","details":"Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.php stores administrator-controlled image_order[] values without enforcing the existing sort-field whitelist. The stored album image_order expression is later concatenated into ORDER BY clauses by admin/batch_manager_global.php, admin/batch_manager_unit.php, include/section_init.inc.php, and include/ws_functions/pwg.categories.php. When at least one album contains at least one photo, an authenticated administrator can store a crafted expression and trigger it in a later album or Batch Manager query to disclose, modify, or disrupt database data. This issue is fixed in version 16.4.0.","aliases":["GHSA-jhp4-7f82-8f6q"],"modified":"2026-09-27T03:47:32.468414768Z","published":"2026-09-25T15:48:55.894Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42324.json"},"references":[{"type":"WEB","url":"https://github.com/Piwigo/Piwigo/releases/tag/16.4.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/42xxx/CVE-2026-42324.json"},{"type":"ADVISORY","url":"https://github.com/Piwigo/Piwigo/security/advisories/GHSA-jhp4-7f82-8f6q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-42324"},{"type":"FIX","url":"https://github.com/Piwigo/Piwigo/commit/ba1f803f8cefd3602ccb9c6f0155cd529510288a"},{"type":"FIX","url":"https://github.com/Piwigo/Piwigo/commit/ef9e65386d76f9c85f1e23a45dd7af14a5b73a47"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/piwigo/piwigo","events":[{"introduced":"0"},{"fixed":"ba1f803f8cefd3602ccb9c6f0155cd529510288a"},{"fixed":"ef9e65386d76f9c85f1e23a45dd7af14a5b73a47"},{"fixed":"bef1a4ac424b4e986589e4cfc9f4d134f1b16f15"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"16.4.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["16.3.0","16.2.0","16.1.0","16.0.0","16.0.0RC3","16.0.0RC2","16.0.0RC1","16.0.0beta2","16.0.0beta1","15.0.0beta3","15.0.0beta2","15.0.0beta1","14.0.0RC2","14.0.0RC1","14.0.0beta3","14.0.0beta2","14.0.0beta1","13.0.0RC4","13.0.0RC3","13.0.0RC2","13.0.0RC1","13.0.0beta2","13.0.0beta1","12.0.0RC2","12.0.0RC1","12.0.0beta2","12.0.0beta1","2.11.0beta4","2.11.0beta3","2.11.0beta2","2.11.0beta1","2.10.0RC1","2.10.0beta2","2.10.0beta1","2.9.0RC2","2.9.0RC1","2.9.0beta2","2.9.0beta1","2.8.0RC2","2.8.0RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-42324.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}