Rathena is an open-source game server and emulation project with a narrow but historically active vulnerability footprint centered on its core server software and the FluxCP control panel. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around memory-safety issues such as heap-based buffer overflows and out-of-bounds writes, alongside web-tier input-handling flaws including cross-site scripting and information disclosure. Defenders maintaining or deploying Rathena-based servers should prioritize patching, particularly for memory-corruption and web-facing components; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rathena over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-58750CRITICAL rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0cc348b are missing a bound check in `chclif_parse | Sep 9, 2025 | 9.1 | 32 | NO | NO |
CVE-2025-58447CRITICAL rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 2f5248b have a heap-based buffer overflow in the l | Sep 9, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-58448CRITICAL rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior to commit 0d89ae0 have a SQL Injection in the PartyBooking c | Sep 9, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-62170HIGH rAthena is an open-source cross-platform MMORPG server. A use-after-free vulnerability exists in the RODEX functionality of rAthena's map-server in versions prior to commit af2f3ba | Oct 13, 2025 | 7.5 | 25 | NO | NO |
CVE-2022-4421MEDIUM A vulnerability was found in rAthena FluxCP. It has been classified as problematic. Affected is an unknown function of the file themes/default/servicedesk/view.php of the component | Dec 12, 2022 | 6.1 | 21 | NO | NO |
CVE-2024-45799MEDIUM FluxCP is a web-based Control Panel for rAthena servers written in PHP. A javascript injection is possible via venders/buyers list pages and shop names, that are currently not sani | Sep 16, 2024 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rathena.
Media articles that mention a CVE ID that affects a product developed by Rathena — matched by CVE ID, not by vendor name.