Qnap Photo Station vulnerabilities

25 known vulnerabilities affecting qnap/photo_station.

Total CVEs
25
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL6HIGH2MEDIUM16LOW1

Vulnerabilities

Page 1 of 2
CVE-2017-20210CRITICALCVSS 9.8v5.2.7v5.4.12025-11-11
CVE-2017-20210 [CRITICAL] CWE-200 CVE-2017-20210: Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.
nvd
CVE-2024-12923LOWCVSS 2.0≥ 6.4.0, < 6.4.52025-08-29
CVE-2024-12923 [LOW] CWE-79 CVE-2024-12923: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote at A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: Photo Station 6.4.5 ( 2025/01/02 ) and later
nvd
CVE-2024-32769MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.32024-11-22
CVE-2024-32769 [MEDIUM] CWE-79 CVE-2024-32769: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
nvd
CVE-2024-32768MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.32024-11-22
CVE-2024-32768 [MEDIUM] CWE-79 CVE-2024-32768: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
nvd
CVE-2024-32770MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.32024-11-22
CVE-2024-32770 [MEDIUM] CWE-79 CVE-2024-32770: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
nvd
CVE-2024-32767MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.32024-11-22
CVE-2024-32767 [MEDIUM] CWE-79 CVE-2024-32767: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
nvd
CVE-2023-47221MEDIUMCVSS 4.9≥ 6.4.0, < 6.4.22024-03-08
CVE-2023-47221 [MEDIUM] CWE-22 CVE-2023-47221: A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerab A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpected files and expose sensitive data via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
nvd
CVE-2023-47562HIGHCVSS 8.8≥ 6.4.0, < 6.4.22024-02-02
CVE-2023-47562 [HIGH] CWE-77 CVE-2023-47562: An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the v An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
nvd
CVE-2023-47561MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.22024-02-02
CVE-2023-47561 [MEDIUM] CWE-79 CVE-2023-47561: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
nvd
CVE-2022-27593CRITICALCVSS 9.1KEVPoCfixed in 5.2.14fixed in 5.4.15+3 more2022-09-08
CVE-2022-27593 [CRITICAL] CWE-610 CVE-2022-27593: An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify system files. We have already fixed the vulnerability in the following versions: QTS 5.0.1: Photo Station 6.1.2 and later QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later QTS
nvd
CVE-2021-44057CRITICALCVSS 9.8fixed in 5.4.13≥ 5.6.0, < 5.7.16+1 more2022-05-05
CVE-2021-44057 [CRITICAL] CWE-287 CVE-2021-44057: An improper authentication vulnerability has been reported to affect QNAP device running Photo Stati An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the security of the system. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.20 ( 2022/02/15 ) and later Photo Station 5.7.16 (
nvd
CVE-2021-34355MEDIUMCVSS 5.4fixed in 5.4.10≥ 5.7.0, < 5.7.13+1 more2021-10-01
CVE-2021-34355 [MEDIUM] CWE-79 CVE-2021-34355: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Statio A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 5.4.10 ( 2021/08/19 ) and later Photo Station 5.7.13 ( 2021/08/19 )
nvd
CVE-2021-34354MEDIUMCVSS 5.4fixed in 6.0.182021-10-01
CVE-2021-34354 [MEDIUM] CWE-79 CVE-2021-34354: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Sta A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
nvd
CVE-2021-34356MEDIUMCVSS 5.4fixed in 6.0.182021-10-01
CVE-2021-34356 [MEDIUM] CWE-79 CVE-2021-34356: A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Sta A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious code. We have already fixed this vulnerability in the following versions of Photo Station: Photo Station 6.0.18 ( 2021/09/01 ) and later
nvd
CVE-2020-2502MEDIUMCVSS 6.1fixed in 6.0.112021-02-17
CVE-2020-2502 [MEDIUM] CWE-79 CVE-2020-2502: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later
nvd
CVE-2020-2491MEDIUMCVSS 6.1fixed in 6.0.12fixed in 5.7.12+3 more2020-12-10
CVE-2020-2491 [MEDIUM] CWE-79 CVE-2020-2491: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. QTS 4.5.1: Photo Station 6.0.12 and later QTS 4.4.3: Photo Station 6.0.12 and later QTS 4.3.6: Photo Station 5.7.12 and later QTS 4.3.4: Photo Station 5.7.13
nvd
CVE-2018-19954MEDIUMCVSS 6.1≥ 5.7.0, < 5.7.11≥ 6.0.0, < 6.0.102020-11-02
CVE-2018-19954 [MEDIUM] CWE-79 CVE-2018-19954: The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
nvd
CVE-2018-19956MEDIUMCVSS 6.1≥ 5.7.0, < 5.7.11≥ 6.0.0, < 6.0.102020-11-02
CVE-2018-19956 [MEDIUM] CWE-79 CVE-2018-19956: The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
nvd
CVE-2018-19955MEDIUMCVSS 6.1≥ 5.7.0, < 5.7.11≥ 6.0.0, < 6.0.102020-11-02
CVE-2018-19955 [MEDIUM] CWE-79 CVE-2018-19955: The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
nvd
CVE-2019-7194CRITICALCVSS 9.8KEVPoCfixed in 6.0.3fixed in 5.7.10+2 more2019-12-05
CVE-2019-7194 [CRITICAL] CWE-22 CVE-2019-7194: This external control of file name or path vulnerability allows remote attackers to access or modify This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
nvd