Photostand is a modestly represented vendor with a narrow product portfolio centered on a single image-display or photo-management application that carries application-layer security responsibilities. The observed weakness classes reflect web-facing input-handling concerns, primarily cross-site scripting vulnerabilities arising from improper neutralization of user-supplied content in rendered pages. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Photostand over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1101MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Photostand 1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) message ("comment") or (2) name fi | Feb 26, 2007 | 4.3 | 21 | NO | YES |
CVE-2007-1102MEDIUM Photostand 1.2.0 allows remote attackers to obtain sensitive information via a ' (quote) character in (1) a PHPSESSID cookie or (2) the id parameter in an article action in index.p | Feb 26, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Photostand.
Media articles that mention a CVE ID that affects a product developed by Photostand — matched by CVE ID, not by vendor name.