Known vulnerabilities in Lightroom
Vendor:
Adobe
Software:
Lightroom
Software CPE:
cpe:2.3:a:adobe:lightroom:*:*:*:*:*:*:*:*
Website:
https://www.adobe.com
Total vulnerabilities:
15
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.7
Breakdown by Severity Chart
15.4
15.3
15.2
15.1
15.0
15.5
10.4
7.4.1
13.5.1
13.5
13.4
13.3
13.2
13.1
13.0
12.5.2
12.5.1
12.5
12.4
12.3
12.2.1
12.2
12.1
12.0.1
12.0
11.5
11.4.1
11.4
11.3.1
11.3
11.2
11.1
11.0
10.3
10.2
10.1.1
9.4
9.2.1
9.1
8.4.1
7.5
7.4
7.3.1
7.3
7.2
6.14
7.1
6.13
2015.13
7.0
6.12
2015.12
6.10.1
2015.10.1
6.10
2015.10
6.9
2015.9
6.8
2015.8
6.7
2015.7
2015.6.1
2015.6
2015.5.1
2015.5
2015.4
2015.3
2015.2.1
2015.2
2015.1.1
6.6.1
6.6
6.5.1
6.5
6.4
6.3
6.2.1
6.2
6.1.1
2015.1
6.1
6.0
5.7.1
5.7
5.6
5.5
5.4
5.3
5.2
5.0
4.4.1
3.4
3.3
3.0
2.7
2.4
2.3
2.2
2.1
2.0
1.4.1
1.4
1.3
1.2
1.1
5.1
4.4
4.3
4.2
4.1
4.0
10.1
10.0
9.3
9.2.0.10
9.2
9.0
8.4
8.3
8.2
8.1
8.0
Vulnerabilities (15)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU142498 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-48441 |
CWE-22 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142499 - Deserialization of Untrusted Data CVE-2026-48397 |
CWE-502 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142500 - Integer overflow CVE-2026-47940 |
CWE-190 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142501 - Out-of-bounds write CVE-2026-48404 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142502 - Out-of-bounds write CVE-2026-48405 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142503 - Out-of-bounds write CVE-2026-48406 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142504 - Out-of-bounds write CVE-2026-48407 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142505 - Out-of-bounds write CVE-2026-48408 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142506 - Out-of-bounds write CVE-2026-48409 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142507 - Out-of-bounds write CVE-2026-48410 |
CWE-787 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU142508 - Incorrect Authorization CVE-2026-48447 |
CWE-863 | High | 15.5 | 14.08.2026 |
SB20260814110 |
||
| #VU98326 - Out-of-bounds read CVE-2024-45145 |
CWE-125 | Low | 7.5, 12.5.2, 13.5.1 | 09.10.2024 |
SB2024100973 |
||
| #VU59040 - Use After Free CVE-2021-43753 |
CWE-416 | Low | 5.1 | 16.12.2021 |
SB2021121608 |
||
| #VU48890 - Uncontrolled Search Path Element CVE-2020-24447 |
CWE-427 | High | 10.1 | 08.12.2020 |
SB2020120850 |
||
| #VU45265 - Uncontrolled Search Path Element CVE-2020-9724 |
CWE-427 | Low | 9.3 | 11.08.2020 |
SB2020081109 |