Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

7 Zip

First CVE: Sep 5, 2007Active for: 19 yearsTotal CVEs: 59

7 Zip is a widely used, open-source file archiver and compression utility with a modest but persistent vulnerability footprint. Despite a small product portfolio centered on the 7 Zip archiver itself and its POSIX variant p7zip, the software maintains prominence in the landscape owing to its ubiquitous deployment across consumer and enterprise systems for handling compressed archives. The vendor's disclosures span a range of parsing and decompression logic that reflects the complexity of supporting multiple archive formats and compression algorithms. Defenders should monitor this vendor's releases given the file-handling role of the software and its position as a common attack surface for malicious archive delivery; current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
34
Total CVEs
More Total CVEs than 98% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
2.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by 7 Zip over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2007
18 years ago
Most Recent CVE
Jun 28, 2026
26 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (34 CVEs).

34 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-0411HIGH
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User i
Jan 25, 20257.089YESNO
CVE-2023-31102HIGH
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
Nov 3, 20237.865NONO
CVE-2025-11001HIGH
7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-
Nov 19, 20257.858NOYES
CVE-2026-48095HIGH
7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed s
Jun 5, 20268.837NONO
CVE-2023-40481HIGH
7-Zip SquashFS File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
May 3, 20247.837NONO
CVE-2024-11477HIGH
7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Nov 22, 20247.834NONO
CVE-2016-2335HIGH
The CInArchive::ReadFileItem method in Archive/Udf/UdfIn.cpp in 7zip 9.20 and 15.05 beta and p7zip allows remote attackers to cause a denial of service (out-of-bounds read) or exec
Jun 7, 20168.833NONO
CVE-2016-2334HIGH
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HF
Dec 13, 20167.832NONO
CVE-2007-4725MEDIUM
Stack consumption vulnerability in AkkyWareHOUSE 7-zip32.dll before 4.42.00.04, as derived from Igor Pavlov 7-Zip before 4.53 beta, allows user-assisted remote attackers to execute
Sep 5, 20076.831NOYES
CVE-2008-6536HIGH
Unspecified vulnerability in 7-zip before 4.5.7 has unknown impact and remote attack vectors, as demonstrated by the PROTOS GENOME test suite for Archive Formats (c10).
Mar 30, 200910.030NONO
View all 34 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products34 CVEs
12%
21%
68%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local18 (52.9%)
Network13 (38.2%)
Unknown3 (8.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low29 (85.3%)
High2 (5.9%)
Unknown3 (8.8%)
User Interaction
None5 (14.7%)
Unknown3 (8.8%)
Required26 (76.5%)
Privileges Required
Low2 (5.9%)
High0 (0.0%)
None29 (85.3%)
Unknown3 (8.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (34 CVEs).

CISA KEV
1 CVE
2.9% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
5.9% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 7 Zip.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 7 Zip — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 7 Zip's Products

View all 6 CNAs →

Top CWEs