rootpwn

high · CVSS v3 7.5 · CVSS v4 8.7

CVE-2026-96673

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated …

Description

Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated attackers to inject SQL by manipulating the album_id path segment. Attackers can supply crafted SQL expressions in the album_id parameter to extract arbitrary data from the database using time-based or blind injection techniques.

Scores

Severity
high
CVSS v2
7.8
CVSS v3
7.5
CVSS v4
8.7
EPSS

← All CVEs