← Vulnerability feed

Vulnerability record · CVE-2020-19213 · published 6 May 2022

CVE-2020-19213: Piwigo sql injection vulnerability

Piwigo · Piwigo

SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

9.8 CVSS 3.1 Critical EPSS 16% · top 3.2% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerability in cat_move.php in piwigo v2.9.5, via the selection parameter to move_categories.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/Piwigo/Piwigo/issues/1010 ExploitIssue TrackingThird Party Advisory
https://github.com/Piwigo/Piwigo/issues/1010 ExploitIssue TrackingThird Party Advisory

Track CVE-2020-19213 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-4648Piwigo vulnerabilityUnspecified vulnerability in Piwigo before 2.6.3 has unknown impact and attack vectors, related to a "security failure."EPSS 1.5%9.8CVE-2023-33361Piwigo sql injection vulnerabilityPiwigo 13.6.0 is vulnerable to SQL Injection via /admin/permalinks.php.EPSS 0.92%9.8CVE-2023-33362Piwigo sql injection vulnerabilityPiwigo 13.6.0 is vulnerable to SQL Injection via in the "profile" function.EPSS 9.1%9.8CVE-2021-32615Piwigo sql injection vulnerabilityPiwigo 11.4.0 allows admin/user_list_backend.php order[0][dir] SQL Injection.EPSS 2.1%9.8CVE-2017-10682Piwigo sql injection vulnerabilitySQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_f…EPSS 8.3%9.8CVE-2016-10105Piwigo information exposure vulnerabilityadmin/plugin.php in Piwigo through 2.8.3 doesn't validate the sections variable while using it to include files. This can cause information disclosur…EPSS 2.4%9.6CVE-2019-13363Piwigo cross-site scripting vulnerabilityadmin.php?page=notification_by_mail in Piwigo 2.9.5 has XSS via the nbm_send_html_mail, nbm_send_mail_as, nbm_send_de…EPSS 1.4%9.6CVE-2019-13364Piwigo cross-site scripting vulnerabilityadmin.php?page=account_billing in Piwigo 2.9.5 has XSS via the vat_number, billing_name, company, or billing_address parameter. This is e…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2020-19213), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.