Lite Xl is a lightweight text editor maintained as a niche open-source project with a focused vulnerability footprint. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lite Xl over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12121HIGH Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command execution through unsanitized shell command construction. This | Nov 20, 2025 | 7.3 | 26 | NO | NO |
CVE-2025-12120HIGH Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, without prompting the user for confirmation. The .lite_project.l | Nov 20, 2025 | 7.3 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lite Xl.
Media articles that mention a CVE ID that affects a product developed by Lite Xl — matched by CVE ID, not by vendor name.