Lhaforge Project maintains a niche compression utility focused on archive handling, with a narrow but persistent exposure centered on search-path handling in file operations. The recurring weakness—uncontrolled search path element—reflects a classic file-system interaction risk inherent to tools that locate and process archives across user-controlled directories. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lhaforge Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2288HIGH Untrusted search path vulnerability in LhaForge Ver.1.6.5 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | Aug 2, 2017 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lhaforge Project.
Media articles that mention a CVE ID that affects a product developed by Lhaforge Project — matched by CVE ID, not by vendor name.