Lightpicture Osuuu Lightpicture

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Osuuu Lightpicture.

By the Year

In 2026 there have been 1 vulnerability in Osuuu Lightpicture with an average score of 7.3 out of ten. Last year, in 2025 Lightpicture had 2 security vulnerabilities published. Right now, Lightpicture is on track to have less security vulnerabilities in 2026 than it did last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 1.45.

Year Vulnerabilities Average Score
2026 1 7.30
2025 2 5.85
2024 2 8.95

It may take a day or so for new Lightpicture vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Osuuu Lightpicture Security Vulnerabilities

osuuu LightPicture 1.2.2 API Upload Endpoint HDC Vulnerability
CVE-2026-6574 7.3 - High - April 19, 2026

A vulnerability has been found in osuuu LightPicture up to 1.2.2. This issue affects some unknown processing of the file /public/install/lp.sql of the component API Upload Endpoint. Such manipulation of the argument key leads to hard-coded credentials. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Use of Hard-coded Credentials

LightPicture 1.2.2 Critical Unrestricted File Upload via Api.php
CVE-2025-1835 6.3 - Medium - March 02, 2025

A vulnerability has been found in osuuu LightPicture 1.2.2 and classified as critical. This vulnerability affects the function upload of the file /app/controller/Api.php. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Authorization

LightPicture <=1.2.2 XSS via SVG File Upload Handler (/api/upload)
CVE-2024-13141 5.4 - Medium - January 05, 2025

A vulnerability classified as problematic was found in osuuu LightPicture up to 1.2.2. This vulnerability affects unknown code of the file /api/upload of the component SVG File Upload Handler. The manipulation of the argument file leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

XSS

OSUUU LightPicture <=1.2.2 PHP Setup.php Remote Unrestricted Upload
CVE-2024-1921 9.8 - Critical - February 27, 2024

A vulnerability, which was classified as critical, was found in osuuu LightPicture up to 1.2.2. Affected is an unknown function of the file /app/controller/Setup.php. The manipulation leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-254856.

Unrestricted File Upload

Critical Hard-Coded Key in osuuu LightPicture <=1.2.2 via TokenVerify
CVE-2024-1920 8.1 - High - February 27, 2024

A vulnerability, which was classified as critical, has been found in osuuu LightPicture up to 1.2.2. This issue affects the function handle of the file /app/middleware/TokenVerify.php. The manipulation leads to use of hard-coded cryptographic key . The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254855.

Use of Hard-coded Cryptographic Key

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Osuuu Lightpicture or by Osuuu? Click the Watch button to subscribe.

Osuuu
Vendor

subscribe