VYPR

Photo Station

by Qnap

CVEs (26)

  • CVE-2018-19954MedNov 2, 2020
    risk 0.40cvss 6.1epss 0.01

    The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions…

  • CVE-2017-13073MedApr 23, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

  • CVE-2023-47221MedMar 8, 2024
    risk 0.36cvss 5.5epss 0.00

    A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the…

  • CVE-2023-47561MedFeb 2, 2024
    risk 0.36cvss 5.5epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 (…

  • CVE-2024-12923MedAug 29, 2025
    risk 0.35cvss 5.4epss 0.00

    A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the…

  • CVE-2013-5760Jun 9, 2014
    risk 0.00cvss epss 0.01

    QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.

Page 2 of 2