CVE-2020-2502: QNAP Photo Station

Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.

This cross-site scripting vulnerability in Photo Station allows remote attackers to inject malicious code. QANP We have already fixed this vulnerability in the following versions of Photo Station. Photo Station 6.0.11 and later

Affected products

  • QNAP Photo Station: before 6.0.11 (fixed in 6.0.11)

Published 2021-02-17. Last modified 2026-06-17.