PT-2026-4266 · Themegoods · Photome

Tran Nguyen Bao Khanh

·

Published

2026-01-22

·

Updated

2026-01-22

·

CVE-2026-24381

CVSS v3.1

5.4

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PhotoMe versions prior to 5.7.2
Description A Server-Side Request Forgery (SSRF) vulnerability exists in ThemeGoods PhotoMe. This allows for Server Side Request Forgery. The vulnerability allows an attacker to make requests on behalf of the server, potentially accessing internal resources or performing actions with the server's privileges.
Recommendations Update PhotoMe to version 5.7.2 or later.

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-24381

Affected Products

Photome