Rapidleech is a file-download manager and leech utility with a narrow product scope but recurring vulnerability surface centered on web-facing input handling and file operations. Its disclosures cluster consistently around cross-site scripting, path traversal, and exposure of sensitive information—weaknesses characteristic of download and file-management applications where user-supplied input directly influences filesystem and output contexts. Current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rapidleech over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-4312MEDIUM ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic has been found in Th3-822 Rapidleech. This affects the function zip_go of the file classes/options/zip.php | Jan 13, 2023 | 6.1 | 21 | NO | NO |
CVE-2009-1090MEDIUM Directory traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequen | Mar 25, 2009 | 6.8 | 19 | NO | NO |
CVE-2011-3798MEDIUM Rapid Leech 2.3-v42-svn322 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2011-5206MEDIUM Cross-site scripting (XSS) vulnerability in notes.php in Rapidleech before 2.3 rev42 SVN r399 allows remote attackers to inject arbitrary web script or HTML via the notes parameter | Oct 4, 2012 | 4.3 | 16 | NO | NO |
CVE-2011-5205MEDIUM Cross-site scripting (XSS) vulnerability in audl.php in Rapidleech 2.3 rev42 SVN r358, rev43 SVN r397, and earlier allows remote attackers to inject arbitrary web script or HTML vi | Oct 4, 2012 | 4.3 | 16 | NO | NO |
CVE-2009-1089MEDIUM Absolute path traversal vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to read arbitrary files via a base64-encoded absolute path in the filen | Mar 25, 2009 | 5.0 | 15 | NO | NO |
CVE-2009-1091MEDIUM Cross-site scripting (XSS) vulnerability in upload.php in Rapidleech rev.36 and earlier allows remote attackers to inject arbitrary web script or HTML via the uploaded parameter. | Mar 25, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rapidleech.
Media articles that mention a CVE ID that affects a product developed by Rapidleech — matched by CVE ID, not by vendor name.