Peazip is a focused, open-source file archiver and compression utility whose vulnerability profile centers on supply-chain and source-integrity concerns, specifically risks around untrusted control of dependencies and embedded web functionality. The recurring weakness classes—inclusion of functionality from untrusted control spheres, web-based code sourcing, and uncontrolled search path elements—reflect the product's reliance on external libraries and plugin mechanisms. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Peazip over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-33026HIGH In PeaZip through 10.4.0, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected instal | Apr 15, 2025 | 7.8 | 22 | NO | NO |
CVE-2023-6891HIGH A vulnerability has been found in PeaZip 9.4.0 and classified as problematic. Affected by this vulnerability is an unknown functionality in the library dragdropfilesdll.dll of the | Dec 17, 2023 | 7.8 | 22 | NO | NO |
CVE-2023-24785MEDIUM An issue in Giorgio Tani peazip v.9.0.0 allows attackers to cause a denial of service via the End of Archive tag function of the peazip/pea UNPEA feature. | Feb 17, 2023 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Peazip.
Media articles that mention a CVE ID that affects a product developed by Peazip — matched by CVE ID, not by vendor name.