Known Vulnerabilities for Ds Photo by Synology
Listed below are 10 of the newest known vulnerabilities associated with "Ds Photo" by "Synology".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33738 | Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without ... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-33691 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. P... | Not Provided | 2026-04-02 | 2026-04-02 |
| CVE-2026-33644 | Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` can be... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-33537 | Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::fromUrl`)... | Not Provided | 2026-03-26 | 2026-03-27 |
| CVE-2026-32537 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK V... | Not Provided | 2026-03-25 | 2026-03-25 |
| CVE-2026-32524 | Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow Photo Engine wplr-sync allows Upload a Web Shell ... | Not Provided | 2026-03-25 | 2026-03-26 |
| CVE-2026-31804 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /pms_image_proxy ... | Not Provided | 2026-03-30 | 2026-04-01 |
| CVE-2026-27360 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 10Web Photo Gallery by ... | Not Provided | 2026-02-19 | 2026-04-01 |
| CVE-2025-69084 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gt3themes Photo Gallery... | Not Provided | 2026-01-06 | 2026-04-01 |
| CVE-2025-68595 | Missing Authorization vulnerability in Trustindex Widgets for Social Photo Feed social-photo-feed-widget allows Exploiting In... | Not Provided | 2025-12-24 | 2026-04-01 |