Lanol's vulnerability footprint is concentrated in FileCodeBox, a file-sharing and management application, with observed issues clustered around authentication handling, input validation, and data protection mechanisms. The recurring weakness classes—authentication bypass, cross-site scripting, path traversal, and sensitive data storage—are typical of web-facing file-handling services where boundary validation and access control are critical to confidentiality and integrity. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lanol over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-51663HIGH A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based rate limit protection and failed attempt restrictions by fak | Nov 19, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-51661HIGH A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is configured to use local filesystem storage. SystemFileStorage. | Nov 19, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-51662MEDIUM A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and earlier. Insufficient input validation allows attackers to inj | Nov 19, 2025 | 5.4 | 20 | NO | NO |
CVE-2024-34525MEDIUM FileCodeBox 2.0 stores a OneDrive password and AWS key in a cleartext env file. | May 6, 2024 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lanol.
Media articles that mention a CVE ID that affects a product developed by Lanol — matched by CVE ID, not by vendor name.