Futo maintains Immich, a self-hosted photo-management application that has surfaced vulnerabilities centered on web-application input handling and access control, including cross-site scripting, open redirects, improper privilege management, and sensitive-data exposure in URLs. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Futo over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25118HIGH immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich application is vulnerable to credential disclosure when a user auth | Apr 3, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-23896HIGH immich is a high performance self-hosted photo and video management solution. Prior to version 2.5.0, API keys can escalate their own permissions by calling the update endpoint, al | Jan 29, 2026 | 8.8 | 27 | NO | NO |
CVE-2026-35455MEDIUM immich is a high performance self-hosted photo and video management solution. Prior to 2.7.0, sStored Cross-Site Scripting (XSS) in the 360° panorama viewer allows any authenticate | Apr 8, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-40096MEDIUM immich is a high performance self-hosted photo and video management solution. Versions prior to 2.7.3 contain an open redirect vulnerability in the shared album functionality, wher | Apr 15, 2026 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Futo.
Media articles that mention a CVE ID that affects a product developed by Futo — matched by CVE ID, not by vendor name.