Yalantis develops a focused portfolio centered on mobile and web components, with its Android image-cropping library UCrop representing the primary disclosed surface. Observed weaknesses cluster around Android component exposure and server-side request forgery, reflecting the attack surface inherent to libraries that handle both inter-process communication and external data fetching; live severity and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yalantis over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14516HIGH A vulnerability was found in Yalantis uCrop 2.2.11. Affected by this issue is the function downloadFile of the file com.yalantis.ucrop.task.BitmapLoadTask.java of the component URL | Dec 11, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-14517MEDIUM A vulnerability was determined in Yalantis uCrop 2.2.11. This affects the function UCropActivity of the file AndroidManifest.xml. Executing manipulation can lead to improper expor | Dec 11, 2025 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yalantis.
Media articles that mention a CVE ID that affects a product developed by Yalantis — matched by CVE ID, not by vendor name.