cbcvebase.

Qnap Photo Station vulnerabilities

25 known vulnerabilities affecting qnap/photo_station.

Total CVEs
25
CISA KEV
4
actively exploited
Public exploits
5
Exploited in wild
5
Severity breakdown
CRITICAL6HIGH2MEDIUM17

Vulnerabilities

Page 2 of 2
CVE-2024-32770P4MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.32024-11-22
CVE-2024-32770 [MEDIUM] CWE-79 CVE-2024-32770: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
nvd
CVE-2024-32767P4MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.32024-11-22
CVE-2024-32767 [MEDIUM] CWE-79 CVE-2024-32767: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to inject malicious code. We have already fixed the vulnerability in the following version: Photo Station 6.4.3 ( 2024/07/12 ) and later
nvd
CVE-2023-47561P4MEDIUMCVSS 5.4≥ 6.4.0, < 6.4.22024-02-02
CVE-2023-47561 [MEDIUM] CWE-79 CVE-2023-47561: A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via a network. We have already fixed the vulnerability in the following version: Photo Station 6.4.2 ( 2023/12/15 ) and later
nvd
CVE-2020-2502P4MEDIUMCVSS 6.1fixed in 6.0.112021-02-17
CVE-2020-2502 [MEDIUM] CWE-79 CVE-2020-2502: This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later
nvd
CVE-2017-13073P4MEDIUMCVSS 6.1≥ 5.2.0, ≤ 5.2.7≥ 5.4.0, ≤ 5.4.3+2 more2018-04-23
CVE-2017-13073 [MEDIUM] CWE-79 CVE-2017-13073: Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3 Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
nvd
Qnap Photo Station vulnerabilities | cvebase