CVE-2026-35048:The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them d
The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configuration file without proper sanitization. On PHP 8+, the `addslashes()` protection is bypassed because it chec