Description SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages. Remediation References CVE-2021-27973 Related Vulnerabilities PHP Numeric Errors Vulnerability (CVE-2016-4070) WordPress Plugin WordPress Download Manager Arbitrary File Upload (2.8.97) OpenSSL Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Vulnerability (CVE-2022-1292) Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4592) WordPress Plugin Ninja Forms Contact Form-The Drag and Drop Form Builder for WordPress Multiple Cross-Site Scripting Vulnerabilities (2.8.8) Severity High Classification CVE-2021-27973 CWE-138 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Tags Missing Update Known Vulnerabilities