Lsfusion develops a business-application platform that, despite a focused product scope, exposes a recurrent vulnerability pattern centered on path-traversal conditions. The durable signal is a file-system access issue that defenders should monitor in any deployment of the Lsfusion platform itself; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lsfusion over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-13262CRITICAL A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java | Nov 17, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-13265CRITICAL A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integ | Nov 17, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-13261MEDIUM A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/Dow | Nov 17, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lsfusion.
Media articles that mention a CVE ID that affects a product developed by Lsfusion — matched by CVE ID, not by vendor name.