{"id":"CVE-2026-62262","summary":"Piwigo: Unauthenticated SQL injection in `pwg.images.filteredSearch.create`","details":"Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the unvalidated value in the search rules, and include/functions_search.inc.php integer-casts only the lower rating bound while concatenating the raw value as the SQL upper bound. This allows error-based or blind extraction of database information and database-dependent time delays through the public search flow. No fixed version is available as of this review.","aliases":["GHSA-hq29-8hhx-5jwc"],"modified":"2026-10-01T03:30:57.087125571Z","published":"2026-09-25T15:46:04.598Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-89"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62262.json","unresolved_ranges":[{"extracted_events":[{"fixed":"17.0.0beta1"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62262.json"},{"type":"ADVISORY","url":"https://github.com/Piwigo/Piwigo/security/advisories/GHSA-hq29-8hhx-5jwc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62262"},{"type":"FIX","url":"https://github.com/Piwigo/Piwigo/commit/9755d88edf38b94bafdedb0b3aba7304a94e2e5c"},{"type":"FIX","url":"https://github.com/Piwigo/Piwigo/commit/aede490a0b3a6c246f1f4689ca86c8fee377a7ae"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/piwigo/piwigo","events":[{"introduced":"0"},{"fixed":"9755d88edf38b94bafdedb0b3aba7304a94e2e5c"},{"fixed":"aede490a0b3a6c246f1f4689ca86c8fee377a7ae"}],"database_specific":{"source":"REFERENCES"}}],"versions":["16.4.0","16.3.0","16.2.0","16.1.0","16.0.0","16.0.0RC3","16.0.0RC2","16.0.0RC1","16.0.0beta2","16.0.0beta1","15.0.0beta3","15.0.0beta2","15.0.0beta1","14.0.0RC2","14.0.0RC1","14.0.0beta3","14.0.0beta2","14.0.0beta1","13.0.0RC4","13.0.0RC3","13.0.0RC2","13.0.0RC1","13.0.0beta2","13.0.0beta1","12.0.0RC2","12.0.0RC1","12.0.0beta2","12.0.0beta1","2.11.0beta4","2.11.0beta3","2.11.0beta2","2.11.0beta1","2.10.0RC1","2.10.0beta2","2.10.0beta1","2.9.0RC2","2.9.0RC1","2.9.0beta2","2.9.0beta1","2.8.0RC2","2.8.0RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62262.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}