Piwigo 2.7.2 Cross Site Scripting / SQL Injection

Piwigo version 2.7.2 suffers from cross site scripting and remote SQL injection vulnerabilities.