CVE-2026-62262
Last modified
CVE-2026-62262 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL.
Description
Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is enabled, an unauthenticated guest can call pwg.images.filteredSearch.create with a crafted ratings[] value and then open the returned search URL. include/ws_functions/pwg.images.php stores the unvalidated value in the search rules, and include/functions_search.inc.php integer-casts only the lower rating bound while concatenating the raw value as the SQL upper bound. This allows error-based or blind extraction of database information and database-dependent time delays through the public search flow. No fixed version is available as of this review.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-62262?
How severe is CVE-2026-62262?
How do I fix CVE-2026-62262?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-62246Kamaji is the Hosted Control Plane Manager for Kubernetes. P…8.5
- CVE-2026-62247Supabase Realtime provides Broadcast, Presence, and Postgres…6.5
- CVE-2026-62248Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMB…
- CVE-2026-62249Weblate is a web-based continuous localization platform used…4.3
- CVE-2026-6225The Taskbuilder – Project Management & Task Management Tool …6.5
- CVE-2026-6226The Frontend Admin by DynamiApps plugin for WordPress is vul…8.8
- CVE-2026-62263Open Access Management (OpenAM) is an access management solu…9.2
- CVE-2026-6227The BackWPup plugin for WordPress is vulnerable to Local Fil…7.2
- CVE-2026-62278LubeLogger is a self-hosted, open-source, web-based vehicle …8.1
- CVE-2026-62279LubeLogger is a self-hosted, open-source, web-based vehicle …7.1
- CVE-2026-6228The Frontend Admin by DynamiApps plugin for WordPress is vul…8.8
- CVE-2026-62280Open Access Management (OpenAM) is an access management solu…6.1
Are you affected by CVE-2026-62262?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
