VulnSea

mobsf has 18 CVEs on record between 2022 and 2026. 4 were published in the last 90 days. The busiest recent month was August 2026 with 4. The median CVSS is 6.5 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
4 prev 0

Products

  • mobsf 18
18
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

mobsf vulnerabilities

CVEs affecting mobsf, newest first. Open any entry for full detail, references, and exploit status.

18 CVEsRSS

CVE-2026-68924Medium· 4.9
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but do…

Sunlitmobsf · mobsfEPSS 0.51%via NVD
CVE-2026-68927Low· 3.0
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before ap…

Sunlitmobsf · mobsfEPSS 0.33%via NVD
CVE-2026-68923Medium· 6.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware only in the deprecated MIDDLEWARE_CLASSES setting and omits it from the active MIDDLEWARE …

Sunlitmobsf · mobsfEPSS 0.19%via NVD
CVE-2026-68922Medium· 5.5
1mo ago

MobSF is a mobile application security testing tool used

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py uses the Android manifest android:icon value to construct paths under the scan resource d…

Sunlitmobsf · mobsfEPSS 0.43%via NVD
CVE-2026-33545Medium· 5.3
6mo ago

MobSF has SQL Injection in its SQLite Database Viewer Utils

MobSF has SQL Injection in its SQLite Database Viewer Utils

Sunlitmobsf · mobsfEPSS 0.28%via OSV
CVE-2026-24490High· 8.1
7mo ago

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

MobSF has Stored XSS via Manifest Analysis - Dialer Code Host Field

Twilightmobsf · mobsfEPSS 0.32%via OSV
CVE-2025-58161Low
1y ago

MobSF Path Traversal in GET /download/<filename> using absolute filenames

MobSF Path Traversal in GET /download/<filename> using absolute filenames

Sunlitmobsf · mobsfEPSS 0.77%via OSV
CVE-2025-58162Medium· 6.5
1y ago

MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction

Sunlitmobsf · mobsfEPSS 0.60%via OSV
CVE-2025-46335Medium
1y ago

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

Mobile Security Framework (MobSF) Allows Stored Cross Site Scripting (XSS) via malicious SVG Icon Upload

Sunlitmobsf · mobsfEPSS 0.30%via OSV
CVE-2025-46730Medium· 6.8
1y ago

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

Mobile Security Framework (MobSF) Allows Web Server Resource Exhaustion via ZIP of Death Attack

Sunlitmobsf · mobsfEPSS 0.48%via OSV
CVE-2025-24804Medium· 6.5
1y ago

MobSF Partial Denial of Service (DoS)

MobSF Partial Denial of Service (DoS)

Sunlitmobsf · mobsfEPSS 0.46%via OSV
CVE-2025-24803High· 8.1
1y ago

MobSF Stored Cross-Site Scripting (XSS)

MobSF Stored Cross-Site Scripting (XSS)

Twilightmobsf · mobsfEPSS 0.39%via OSV
CVE-2025-24805Medium· 6.5
1y ago

MobSF Local Privilege Escalation

MobSF Local Privilege Escalation

Sunlitmobsf · mobsfEPSS 0.36%via OSV
CVE-2024-53999Medium· 6.1
1y ago

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality

Sunlitmobsf · mobsfEPSS 0.52%via OSV
CVE-2024-43399High· 8.0
2y ago

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

Mobile Security Framework (MobSF) has a Zip Slip Vulnerability in .a Static Library Files

Twilightmobsf · mobsfEPSS 0.96%via OSV
CVE-2024-41955Medium· 5.2PoC
2y ago

MobSF vulnerable to Open Redirect in Login Redirect

MobSF vulnerable to Open Redirect in Login Redirect

Twilightmobsf · mobsfEPSS 1.0%via OSV
CVE-2024-31215Medium· 6.3
2y ago

Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check

Mobile Security Framework (MobSF) vulnerable to SSRF in firebase database check

Sunlitmobsf · mobsfEPSS 0.51%via OSV
CVE-2022-41547High· 7.5
3y ago

MobSF allows attackers to read arbitrary files via a crafted HTTP request

MobSF allows attackers to read arbitrary files via a crafted HTTP request

Twilightmobsf · mobsfEPSS 1.3%via OSV
mobsf vulnerabilities (CVEs) · VulnSea