All 5 CVE vulnerabilities found in LightPicture, with AI-generated Chinese analysis, references, and POCs.
Vendor: osuuu
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-6574 | osuuu LightPicture API Upload Endpoint lp.sql hard-coded credentials CWE-798 | 7.3 | High | 2026-04-19 |
| CVE-2025-1835 | osuuu LightPicture Api.php upload unrestricted upload CWE-434 | 6.3 | Medium | 2025-03-02 |
| CVE-2024-13141 | osuuu LightPicture SVG File Upload upload cross site scripting CWE-79 | 3.5 | Low | 2025-01-05 |
| CVE-2024-1921 | osuuu LightPicture Setup.php unrestricted upload CWE-434 | 4.7 | Medium | 2024-02-27 |
| CVE-2024-1920 | osuuu LightPicture TokenVerify.php handle hard-coded key CWE-321 | 5.6 | Medium | 2024-02-27 |
All 5 known CVE vulnerabilities affecting LightPicture with full Chinese analysis, references, and POCs where available.