Piwigo before 13.6.0 was discovered to contain a SQL injection vulnerability via the order[0][dir] parameter at userlistbackend.php.