Loading vulnerability details…
CVSS v3.1
N/A
EPSS
1.81%
Published
Feb 20, 2015
Modified
May 6, 2026
Public PoC / Exploit (1)
All weaponized →Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
Weaknesses (CWE)
Affected Products (1)
References (14)