Known vulnerabilities in Freecad

Vendor: Freecadweb
Software: Freecad
Software CPE: cpe:2.3:a:freecadweb:freecad:*:*:*:*:*:*:*:*
Total vulnerabilities: 8
Public exploits: 5
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Freecad Freecad is affected by 8 known vulnerabilities: 7 high, 1 medium Critical High Medium Low

Vulnerabilities (8)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU139917 - Improper input validation
CVE-2026-73233
CWE-20 High
Available
No
1.1.2 28.07.2026 SB20260728119
SB2026082731
#VU139904 - Improper Restriction of XML External Entity Reference ('XXE')
CVE-2026-73235
CWE-611 Medium
Available
No
1.1.2 28.07.2026 SB20260728119
SB2026082731
#VU139902 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-73234
CWE-22 High
Available
No
1.1.2 28.07.2026 SB20260728119
SB2026082731
#VU139901 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-34789
CWE-94 High
Available
No
1.1.2 28.07.2026 SB20260728119
SB2026082731
#VU139900 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-34399
CWE-94 High
No
No
1.1.1 28.07.2026 SB20260728117
SB2026082731
#VU139899 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-34398
CWE-94 High
Available
No
1.1.1 28.07.2026 SB20260728117
SB2026082731
#VU67353 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-45845
CWE-78 High
No
No
0.20 14.09.2022 SB2022091455
SB2022091456
#VU67352 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2021-45844
CWE-78 High
No
No
0.20 14.09.2022 SB2022091455
SB2022091456