Pf4j is a lightweight plugin framework for Java applications that enables dynamic plugin loading and management, and its vulnerability profile centers on path-traversal weaknesses in how the framework handles plugin artifact paths and directory access. This represents a structural risk inherent to plugin systems that must parse and validate user-controlled or untrusted plugin locations; defenders using this framework should validate plugin sources and restrict filesystem access accordingly. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pf4j Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-70952HIGH pf4j before 20c2f80 has a path traversal vulnerability in the extract() function of Unzip.java, where improper handling of zip entry names can allow directory traversal or Zip Slip | Mar 25, 2026 | 7.5 | 24 | NO | NO |
CVE-2023-40827HIGH An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter. | Aug 28, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-40826HIGH An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter. | Aug 28, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-40828HIGH An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip method in the extract function. | Aug 28, 2023 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pf4j Project.
Media articles that mention a CVE ID that affects a product developed by Pf4j Project — matched by CVE ID, not by vendor name.