Cewe's vulnerability footprint centers on a narrowly scoped portfolio of photo management and display applications, specifically the Photo Importer and Photo Show products. The durable signal reflects storage and authentication handling, with observed weaknesses clustering around sensitive data persistence and password management practices. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cewe over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-25552HIGH CEWE PHOTO SHOW 6.4.3 contains a denial of service vulnerability that allows attackers to crash the application by submitting an excessively long buffer to the password field. Atta | Mar 21, 2026 | 7.5 | 25 | NO | NO |
CVE-2019-25553MEDIUM CEWE PHOTO IMPORTER 6.4.3 contains a denial of service vulnerability that allows local attackers to crash the application by importing a specially crafted image file. Attackers can | Mar 21, 2026 | 6.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cewe.
Media articles that mention a CVE ID that affects a product developed by Cewe — matched by CVE ID, not by vendor name.