Trovebox is a self-hosted photo management and sharing platform with a focused vulnerability footprint centered on its core product. The durable signal reflects application-layer weaknesses including SQL injection, server-side request forgery, and weak password recovery mechanisms, which are characteristic of web-facing content and credential management systems. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Trovebox over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000554CRITICAL Trovebox version <= 4.0.0-rc6 contains a Unsafe password reset token generation vulnerability in user component that can result in Password reset. This attack appear to be exploita | Jun 26, 2018 | 9.8 | 26 | NO | NO |
CVE-2018-1000553HIGH Trovebox version <= 4.0.0-rc6 contains a Server-Side request forgery vulnerability in webhook component that can result in read or update internal resources. This attack appear to | Jun 26, 2018 | 8.8 | 24 | NO | NO |
CVE-2018-1000552HIGH Trovebox version <= 4.0.0-rc6 contains a SQL Injection vulnerability in album component that can result in SQL code injection. This attack appear to be exploitable via HTTP request | Jun 26, 2018 | 8.8 | 24 | NO | NO |
CVE-2018-1000551HIGH Trovebox version <= 4.0.0-rc6 contains a PHP Type juggling vulnerability in album view component that can result in Authentication bypass. This attack appear to be exploitable via | Jun 26, 2018 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Trovebox.
Media articles that mention a CVE ID that affects a product developed by Trovebox — matched by CVE ID, not by vendor name.