CVE-2026-107125: Xnview Classic

Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A flaw has been found in XnView Classic 2.52.5. Impacted is an unknown function of the component FLI File Parser. This manipulation of the argument starting_line causes heap-based buffer overflow. Remote exploitation of the attack is possible. Upgrading to version 2.52.6 is recommended to address this issue. Upgrading the affected component is advised.

Affected products

  • Xnview Classic: version 2.52.5 only

Published 2026-10-07. Last modified 2026-10-07.