Skip to main content

Vendor/product archive

qnap / photo_station CVEs

Beta · best-effort

26 CVEs tagged to qnap / photo_station5 Critical, 6 High, 14 Medium, 1 Low, 0 Unrated.

CVE-2017-20210

Published Nov 11, 2025

Photo Station 5.4.1 & 5.2.7 include the security fix for the vulnerability related to the XMR mining programs identified by internal research.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-12923

Published Aug 29, 2025

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-32770

Published Nov 22, 2024

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to i…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32769

Published Nov 22, 2024

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to i…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32768

Published Nov 22, 2024

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to i…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32767

Published Nov 22, 2024

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow remote attackers who have gained user access to i…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47221

Published Mar 8, 2024

A path traversal vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated administrators to read the contents of unexpect…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-47562

Published Feb 2, 2024

An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to execute commands via a network.…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47561

Published Feb 2, 2024

A cross-site scripting (XSS) vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could allow authenticated users to inject malicious code via…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-27593

Published Sep 8, 2022

An externally controlled reference to a resource vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, This could allow an attacker to modify sys…

CVSS 10.0 · Critical
evidence mentions
4
Buzz score
47.6
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2021-44057

Published May 5, 2022

An improper authentication vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows attackers to compromise the securit…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2021-34356

Published Oct 1, 2021

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malici…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34355

Published Oct 1, 2021

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP NAS running Photo Station. If exploited, this vulnerability allows remote attackers to inject malicious…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-34354

Published Oct 1, 2021

A cross-site scripting (XSS) vulnerability has been reported to affect QNAP device running Photo Station. If exploited, this vulnerability allows remote attackers to inject malici…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-2502

Published Feb 17, 2021

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2491

Published Dec 10, 2020

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions…

CVSS 6.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-19956

Published Nov 2, 2020

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malici…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19955

Published Nov 2, 2020

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malici…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-19954

Published Nov 2, 2020

The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malici…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7195

Published Dec 5, 2019

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7194

Published Dec 5, 2019

This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
42.5
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2019-7192

Published Dec 5, 2019

This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station t…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
45.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2018-0722

Published Feb 1, 2019

Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-0715

Published Aug 27, 2018

Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-13073

Published Apr 23, 2018

Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary w…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 26 CVEsPage 1 of 2