Photoshop
Vendor:
First CVE: Jun 13, 2005 · Active for 21 years
94
Total CVEs
More Total CVEs than 99% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Photoshop over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 13, 2005
21 years ago
Most Recent CVE
Apr 14, 2026
104 days ago
CVE Severity & Scoring
Photoshop94 CVEs
15%
81%
All CVEs352,727 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local77 (81.9%)
Network7 (7.4%)
Unknown10 (10.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low84 (89.4%)
High0 (0.0%)
Unknown10 (10.6%)
User Interaction
None2 (2.1%)
Unknown10 (10.6%)
Required82 (87.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None84 (89.4%)
Unknown10 (10.6%)
Top CVEs
Signals from CVEs in this product scope (94 CVEs).
94 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2365HIGH Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assisted remote attackers to execute arbitrary code via a crafted | Apr 30, 2007 | 9.3 | 63 | NO | YES |
CVE-2007-2244HIGH Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DI | Apr 25, 2007 | 9.3 | 58 | NO | YES |
CVE-2011-2131HIGH Adobe Photoshop 12.0 in Creative Suite 5 (CS5) and 12.1 in Creative Suite 5.1 (CS5.1) allows remote attackers to execute arbitrary code or cause a denial of service (memory corrupt | Aug 11, 2011 | 9.3 | 53 | NO | YES |
CVE-2012-2027HIGH Use-after-free vulnerability in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via a crafted TIFF (aka .TIF | May 9, 2012 | 9.3 | 45 | NO | YES |
CVE-2008-1765HIGH Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remote attackers and physically proximate attackers to execute ar | Apr 23, 2008 | 9.3 | 43 | NO | YES |
CVE-2010-3127HIGH Untrusted search path vulnerability in Adobe PhotoShop CS2 through CS5 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attack | Aug 26, 2010 | 9.3 | 41 | NO | YES |
CVE-2012-2028HIGH Buffer overflow in Adobe Photoshop CS5 12.x before 12.0.5 and CS5.1 12.1.x before 12.1.1 allows remote attackers to execute arbitrary code via unspecified vectors. | May 9, 2012 | 9.3 | 33 | NO | NO |
CVE-2017-11303CRITICAL An issue was discovered in Adobe Photoshop 18.1.1 (2017.1.1) and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbi | Dec 9, 2017 | 9.8 | 31 | NO | NO |
CVE-2011-2164HIGH Multiple unspecified vulnerabilities in Adobe Photoshop before 12.0.4 have unknown impact and attack vectors. | May 20, 2011 | 10.0 | 31 | NO | NO |
CVE-2026-27289HIGH Photoshop Desktop versions 27.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocat | Apr 14, 2026 | 7.8 | 30 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (94 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
6.4% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (94 CVEs).
Media Mentions
Signals from CVEs in this product scope (94 CVEs).
Top CNAs Publishing CVEs For Photoshop
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| le | 1 | 4.6 | 1.3% | 0 | 0 |
| 9.0.2 | 7 | 8.7 | 17.2% | 0 | 4 |
| 9.0.1 | 4 | 9.5 | 9.5% | 0 | 2 |
| 9.0 | 4 | 9.5 | 9.5% | 0 | 2 |
| 8.0 | 5 | 8.1 | 5.9% | 0 | 1 |
| 7.0.1 | 2 | 9.3 | 10.2% | 0 | 1 |
| 7.0 | 4 | 8.3 | 6.4% | 0 | 1 |
| 6.0.1 | 2 | 9.3 | 10.2% | 0 | 1 |
| 6.0 | 2 | 9.3 | 10.2% | 0 | 1 |
| 5.0 | 2 | 9.3 | 10.2% | 0 | 1 |
| 4.0 | 2 | 9.3 | 10.2% | 0 | 1 |
| 3.2 | 1 | 9.3 | 20.0% | 0 | 1 |
| 3.0 | 2 | 9.3 | 10.2% | 0 | 1 |
| 26.0 | 1 | 7.8 | 0.5% | 0 | 0 |
| 25.0 | 2 | 5.5 | 0.3% | 0 | 0 |
| 2.5 | 2 | 9.3 | 10.2% | 0 | 1 |
| 12.1 | 1 | 9.3 | 22.2% | 0 | 1 |
| 12.0.4 | 2 | 9.3 | 10.2% | 0 | 1 |
| 12.0.3 | 2 | 9.3 | 10.2% | 0 | 1 |
| 12.0.2 | 3 | 9.5 | 8.1% | 0 | 1 |