Frostwire is a peer-to-peer file-sharing application with a modest vulnerability footprint centered on its single product line. The observed exposure reflects XML external-entity handling in the application's data-parsing logic, a structural weakness class that merits attention in any document-processing context. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Frostwire over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-1000828CRITICAL FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidenti | Dec 20, 2018 | 9.0 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Frostwire.
Media articles that mention a CVE ID that affects a product developed by Frostwire — matched by CVE ID, not by vendor name.