VYPR

photoview

by Photoview

CVEs (1)

  • CVE-2026-96271HigSep 23, 2026
    risk 0.46cvss 7.1epss

    Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows authenticated users to create share links for albums owned by other users. Attackers can supply arbitrary album IDs to generate working share tokens for victim…