Piwigo v11.5 was discovered to contain a SQL injection vulnerability via the parameter pwg_token in /admin/batch_manager_global.php.Referenceshttps://github.com/Piwigo/Piwigo/issues/1469