Skip to main content
Vulnerability Database/CVE-2026-62262

CVE-2026-62262: Piwigo Photo Gallery SQL Injection Flaw

CVE-2026-62262 is a SQL injection flaw in Piwigo photo gallery that allows unauthenticated attackers to extract database information through crafted rating values. This article covers technical details, affected versions, and steps to protect your installation.

Published:

CVE-2026-62262 Overview

CVE-2026-62262 is a SQL injection vulnerability in Piwigo, an open source photo gallery application. The flaw affects versions 17.0.0beta1 and earlier when the rating feature is enabled. An unauthenticated attacker can call the pwg.images.filteredSearch.create web service with a crafted ratings[] value and open the returned search URL to trigger injection in the public search flow.

Critical Impact

Unauthenticated attackers can extract arbitrary database contents through error-based or blind SQL injection and induce database-dependent time delays. No fixed release is available as of this review.

Affected Products

  • Piwigo photo gallery, versions 17.0.0beta1 and earlier
  • Deployments with the rating feature ($conf['rate']) enabled
  • Public-facing instances exposing the pwg.images.filteredSearch.create web service

Discovery Timeline

  • 2026-09-25 - CVE-2026-62262 published to NVD
  • 2026-09-29 - Last updated in NVD database

Technical Details for CVE-2026-62262

Vulnerability Analysis

The vulnerability is a SQL injection flaw classified under [CWE-89]. The Piwigo web service pwg.images.filteredSearch.create accepts an array parameter named ratings[] and stores it directly into the search rules structure. When the resulting search URL is opened, the search engine builds a SQL WHERE clause using these values. The upper bound of each rating range is concatenated into the SQL string without sanitization, enabling injection through the public search flow without authentication.

Root Cause

The root cause lies in two files. In include/ws_functions/pwg.images.php, the handler stored $params['ratings'] into $search['fields']['ratings'] without validating that each element matched a numeric pattern. In include/functions_search.inc.php, the query builder applied intval() only to the lower bound while concatenating the raw $r value as the upper bound: rating_score >= '.(intval($r)-1).' AND rating_score < '.$r. Attacker-controlled strings reached the SQL layer unescaped.

Attack Vector

An unauthenticated remote attacker issues an API call to pwg.images.filteredSearch.create with a ratings[] entry containing injected SQL syntax. The server returns a search identifier, which the attacker opens through the public search URL. Execution of the search triggers the malformed query, producing either explicit database errors or measurable time delays suitable for blind extraction of credentials, session data, or other stored content.

php
// Patch in include/ws_functions/pwg.images.php - input validation
  if ($conf['rate'] and isset($params['ratings']))
  {
+    foreach ($params['ratings'] as $rate)
+    {
+      if (!preg_match('/^\d+$/i', $rate))
+      {
+        return new PwgError(WS_ERR_INVALID_PARAM, 'Invalid parameter ratings');
+      }
+    }
+
     $search['fields']['ratings'] = $params['ratings'];
  }

// Patch in include/functions_search.inc.php - integer cast on upper bound
-   $filter_clauses[] = '(rating_score >= '.(intval($r)-1).' AND rating_score < '.$r.')';
+   $filter_clauses[] = '(rating_score >= '.(intval($r)-1).' AND rating_score < '.intval($r).')';

Source: Piwigo commit 9755d88 and commit aede490

Detection Methods for CVE-2026-62262

Indicators of Compromise

  • HTTP POST requests to ws.php invoking method=pwg.images.filteredSearch.create with non-numeric values in the ratings[] array.
  • Access-log entries loading the resulting search URL (typically index.php?/search/<id>) immediately after suspicious API calls.
  • Database errors or query execution times correlated with search-page requests from the same client IP.

Detection Strategies

  • Inspect web server logs for ratings[] parameters containing characters outside [0-9], such as quotes, parentheses, or SQL keywords.
  • Monitor the PHP/MySQL error log for syntax errors referencing rating_score or the filter_clauses block.
  • Alert on anomalous latency spikes on search endpoints that correlate with blind SQL injection payloads using SLEEP() or BENCHMARK().

Monitoring Recommendations

  • Deploy a web application firewall rule to block requests to pwg.images.filteredSearch.create where any ratings[] element is non-numeric.
  • Enable database query logging and baseline normal query durations for the Piwigo search path.
  • Correlate web service calls with subsequent /search/ page loads from the same source to identify two-step exploitation chains.

How to Mitigate CVE-2026-62262

Immediate Actions Required

  • Disable the rating feature by setting $conf['rate'] = false; in Piwigo configuration until a fixed release is published.
  • Restrict access to ws.php from untrusted networks through authentication or IP allowlisting where feasible.
  • Apply the upstream patches from commits 9755d88 and aede490 manually if running from source.

Patch Information

No tagged release containing the fix is available at the time of this review. The upstream repository has merged commits 9755d88 and aede490, which add a preg_match('/^\d+$/i', $rate) validation in pwg.images.php and wrap the upper bound with intval() in functions_search.inc.php. See the GitHub Security Advisory GHSA-hq29-8hhx-5jwc for the authoritative advisory.

Workarounds

  • Set $conf['rate'] = false; to disable rating and prevent the vulnerable code path from executing.
  • Deploy a WAF rule rejecting any pwg.images.filteredSearch.create request where ratings[] elements fail a strict ^\d+$ regex.
  • Apply the two upstream commits as a hotfix to local installations until a tagged version is available.
bash
# Disable the rating feature in Piwigo local configuration
# File: local/config/config.inc.php
echo "<?php\n\$conf['rate'] = false;\n" >> local/config/config.inc.php

# Example WAF rule (ModSecurity) to reject non-numeric ratings[] values
SecRule ARGS_NAMES "@rx ^ratings\[\]$" \
  "id:1026062262,phase:2,deny,status:400,\
   chain,msg:'Piwigo CVE-2026-62262 ratings[] injection attempt'"
  SecRule ARGS "!@rx ^[0-9]+$" "t:none"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.