Manyfold is a niche 3D model management and sharing application whose vulnerability profile centers on access control and command-handling flaws, including authorization bypass through user-controlled keys, OS command injection, and insufficient session expiration. These weaknesses reflect the application's need to mediate access to stored assets and execute backend operations, and defenders managing Manyfold deployments should focus on access controls and input validation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Manyfold over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27635HIGH Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.0, when model render gen | Feb 26, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-27933MEDIUM Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Versions prior to 0.133.0 are vulnerable to ses | Feb 26, 2026 | 6.8 | 23 | NO | NO |
CVE-2026-28225MEDIUM Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on 3d printing. Prior to version 0.133.1, the `get_model` metho | Feb 26, 2026 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Manyfold.
Media articles that mention a CVE ID that affects a product developed by Manyfold — matched by CVE ID, not by vendor name.