CVE-2026-27885

Piwigo: SQL Injection in Activity.getList

Piwigo is an open source photo gallery application for the web. Prior to version 16.3.0, a SQL Injection vulnerability was discovered in Piwigo affecting the Activity List API endpoint. This vulnerability allows an authenticated administrator to extract sensitive data from the database, including user credentials, email addresses, and all stored content. This issue has been patched in version 16.3.0.


We have discovered 1,948 live websites that are affected by CVE-2026-27885.

Run a Free Instant Scan




Affected Software

Product  Piwigo
Category Photo Galleries
Vulnerable Domains1,948 live websites (79% of Piwigo install base)
Vulnerable Versions
  • from 0 through 16.3
Vulnerable Versions Count36 versions ( 97% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Apr 3, 2026
  • Updated - Apr 6, 2026

Website Distribution by Country

Number of websites using CVE-2026-27885
United States382 websites



Germany480 websites
France357 websites
Netherlands87 websites
Russia69 websites
GB63 websites
Switzerland61 websites
Czech Republic58 websites
Poland39 websites
Austria34 websites

Website Distribution by TLD

Number of websites using CVE-2026-27885
.com457 websites
.de303 websites
.net191 websites
.fr148 websites
.org147 websites
.nl74 websites
.ru56 websites
.ch51 websites
.at47 websites
.cz38 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-27885

Top websites that are affected by CVE-2026-27885. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************.de Germany***,***
*******.fr France***,***
***********.net United States***,***
*****.*****.net United States***,***
*****.***********.de Germany***,***
****************.ae United Arab Emirates***,***
*********.com United States***,***
*************.com United States***,***
*****.com United States***,***
***********.org United States***,***
See full domain list

FAQ

CVE-2026-27885 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Piwigo
A total of 1,948 websites have been identified as vulnerable to CVE-2026-27885, based on global website indexing conducted by WebTechSurvey.
The Piwigo is affected by the CVE-2026-27885 vulnerability.
Piwigo versions up to 16.3 are vulnerable to CVE-2026-27885.
CVE-2026-27885 is resolved in version 16.3 of Piwigo.