VendorsQNAPphoto_stationall versions
Vulnerabilities

QNAP Photo Station

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2022-27593
DeadBolt Ransomware
Published 2022-09-08 · Analyzed
10.0KEVEPSS 0.879
CVE-2021-44057
Improper authentication in Photo Station
Published 2022-05-05 · Modified
10.0EPSS 0.009
CVE-2019-7195
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.897
CVE-2019-7192
This improper access control vulnerability allows remote attackers to gain unauthorized access to the system. To fix these vulnerabilities, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.881
CVE-2019-7194
This external control of file name or path vulnerability allows remote attackers to access or modify system files. To fix the vulnerability, QNAP recommend updating Photo Station to their latest versions.
Published 2019-12-05 · Analyzed
9.8KEVEPSS 0.831
CVE-2017-20210
Photo Station
Published 2025-11-11 · Analyzed
9.8EPSS 0.003
CVE-2023-47562
Photo Station
Published 2024-02-02 · Modified
8.8EPSS 0.011
CVE-2021-34355
Stored XSS Vulnerability in Photo Station
Published 2021-10-01 · Modified
7.6EPSS 0.006
CVE-2021-34356
Stored XSS Vulnerability in Photo Station
Published 2021-10-01 · Modified
7.6EPSS 0.006
CVE-2021-34354
Stored Cross-site Scripting Vulnerability in Photo Station
Published 2021-10-01 · Modified
7.6EPSS 0.006
CVE-2018-0722
Path Traversal vulnerability in Photo Station versions: 5.7.2 and earlier in QTS 4.3.4, 5.4.4 and earlier in QTS 4.3.3, 5.2.8 and earlier in QTS 4.2.6 could allow remote attackers to access sensitive information on the device.
Published 2019-02-01 · Modified
7.5EPSS 0.017
CVE-2024-32767
Photo Station
Published 2024-11-22 · Analyzed
6.3EPSS 0.004
CVE-2024-32768
Photo Station
Published 2024-11-22 · Analyzed
6.3EPSS 0.004
CVE-2024-32769
Photo Station
Published 2024-11-22 · Analyzed
6.3EPSS 0.004
CVE-2024-32770
Photo Station
Published 2024-11-22 · Analyzed
6.3EPSS 0.004
CVE-2018-0715
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
Published 2018-08-27 · Modified
6.11 PoCEPSS 0.031
CVE-2020-2491
Cross-site Scripting Vulnerability in Photo Station
Published 2020-12-10 · Modified
6.1EPSS 0.010
CVE-2018-19956
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Published 2020-11-02 · Modified
6.1EPSS 0.009
CVE-2018-19955
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Published 2020-11-02 · Modified
6.1EPSS 0.009
CVE-2018-19954
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Published 2020-11-02 · Modified
6.1EPSS 0.009
CVE-2020-2502
Cross-site Scripting Vulnerability in Photo Station
Published 2021-02-17 · Modified
6.1EPSS 0.008
CVE-2017-13073
Cross-site scripting (XSS) vulnerability in QNAP NAS application Photo Station versions 5.2.7, 5.4.3, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.
Published 2018-04-23 · Modified
6.1EPSS 0.008
CVE-2023-47221
Photo Station
Published 2024-03-08 · Analyzed
5.5EPSS 0.005
CVE-2023-47561
Photo Station
Published 2024-02-02 · Modified
5.5EPSS 0.003
CVE-2024-12923
Photo Station
Published 2025-08-29 · Analyzed
5.4EPSS 0.002
CVE-2013-5760
QNAP Photo Station before firmware 4.0.3 build0912 allows remote attackers to list OS user accounts via a request to photo/p/api/list.php.
Published 2014-06-09 · Modified
5.0EPSS 0.013