C4illin's vulnerability profile centers on its ConvertX file-conversion product, with observed weaknesses clustering around file-handling and path-manipulation issues: path traversal, external control of file names and paths, and unrestricted upload of dangerous file types. These flaws reflect the inherent risks of a conversion utility that processes user-supplied files across filesystem operations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by C4illin over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66449HIGH ConvertXis a self-hosted online file converter. In versions prior to 0.16.0, the endpoint `/upload` allows an authenticated user to write arbitrary files on the system, overwriting | Dec 16, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-24741HIGH ConvertXis a self-hosted online file converter. In versions prior to 0.17.0, the `POST /delete` endpoint uses a user-controlled `filename` value to construct a filesystem path and | Jan 27, 2026 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by C4illin.
Media articles that mention a CVE ID that affects a product developed by C4illin — matched by CVE ID, not by vendor name.