CMS Piwigo 2.7.3 Cross Site Scripting / SQL Injection

CMS Piwigo versions 2.7.3 and below suffer from cross site scripting and remote SQL injection vulnerabilities.