futo records
4 published records for vendor futo.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-269 Improper Privilege Management1
- CWE-598 Use of HTTP Request With Sensitive Query String1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2026-23896No exploit | immich API Key Privilege Escalation vulnerabilityfuto · immich · CWE-269 | High8.8 | — | 0.3% | Jan 29, 2026 |
25Monitor | CVE-2026-25118No exploit | immich-server: Insecure Transmission of Authentication Credentials via Password Parameter in HTTP Request Query String When Accessing Shared Albumsfuto · immich · CWE-598 | Medium6.3 | — | 0.4% | Apr 3, 2026 |
21Monitor | CVE-2026-35455Proof of concept | immich has Stored XSS via OCR Text in 360° Panorama Viewerfuto · immich · CWE-79 | Medium5.4 | — | 0.3% | Apr 8, 2026 |
20Monitor | CVE-2026-40096No exploit | immich: Open Redirect via Shared Album namefuto · immich · CWE-79 | Medium5.1 | — | 0.2% | Apr 15, 2026 |
- CVE-2026-2389635Monitor
immich API Key Privilege Escalation vulnerability
HighCVSS 8.8No exploitEPSS 0%futo · immichJan 29, 2026
- CVE-2026-2511825Monitor
immich-server: Insecure Transmission of Authentication Credentials via Password Parameter in HTTP Request Query String When Accessing Shared Albums
MediumCVSS 6.3No exploitEPSS 0%futo · immichApr 3, 2026
- CVE-2026-3545521Monitor
immich has Stored XSS via OCR Text in 360° Panorama Viewer
MediumCVSS 5.4Proof of conceptEPSS 0%futo · immichApr 8, 2026
- CVE-2026-4009620Monitor
immich: Open Redirect via Shared Album name
MediumCVSS 5.1No exploitEPSS 0%futo · immichApr 15, 2026