VendorsSandboxie-Plussandboxieall versions
Vulnerabilities

Sandboxie-Plus (David Xanatos) Sandboxie

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

17CVEs
CVE-2018-18748
Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's intended functionality
Published 2018-10-28 · Modified
10.0EPSS 0.024
CVE-2025-64721
Sandboxie's Integer Overflow in SbieIniServer::RC4Crypt allows sandbox escape and SYSTEM compromise
Published 2025-12-11 · Analyzed
10.0EPSS 0.007
CVE-2026-34458
Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly
Published 2026-05-05 · Analyzed
9.3EPSS 0.003
CVE-2024-49360
Path traversal in Sandboxie
Published 2024-11-29 · Analyzed
9.2EPSS 0.005
CVE-2026-34464
Sandboxie-Plus NamedPipeServer OpenHandler stack overflow via unterminated server field
Published 2026-05-05 · Analyzed
8.8EPSS 0.002
CVE-2026-34459
Sandboxie-Plus sandbox escape via uninitialized memory leak and stack overflow in GetRawInputDeviceInfoSlave
Published 2026-05-05 · Analyzed
8.8EPSS 0.002
CVE-2026-32603
Sandboxie kernel driver denial of service via malformed IOCTL from sandboxed process
Published 2026-05-05 · Analyzed
8.2EPSS 0.002
CVE-2025-46714
Sandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_GET_SECURE_PARAM)
Published 2025-05-22 · Analyzed
7.8EPSS 0.002
CVE-2025-46715
Sandboxie Arbitrary Kernel Write in SbieDrv.sys API (API_GET_SECURE_PARAM)
Published 2025-05-22 · Analyzed
7.8EPSS 0.002
CVE-2025-46713
Sandboxie has Pool Buffer Overflow in SbieDrv.sys API (API_SET_SECURE_PARAM)
Published 2025-05-22 · Analyzed
7.8EPSS 0.002
CVE-2026-34461
Sandboxie-Plus SbieIniServer RunSbieCtrl stack buffer overflow allows local privilege escalation
Published 2026-05-05 · Analyzed
7.8EPSS 0.002
CVE-2026-34462
Sandboxie-Plus ProcessServer boxname stack buffer overflows via unterminated wide string copy
Published 2026-05-05 · Analyzed
7.8EPSS 0.002
CVE-2026-34596
Sandboxie-Plus local privilege escalation via TOCTOU race condition in UpdUtil addon installation
Published 2026-05-05 · Analyzed
7.0EPSS 0.001
CVE-2019-25551
Sandboxie 5.30 Denial of Service via Program Alerts Buffer Overflow
Published 2026-03-21 · Analyzed
6.9EPSS 0.002
CVE-2025-54422
Sandboxie exposes encrypted sandbox key during password change
Published 2025-07-29 · Analyzed
6.9EPSS 0.001
CVE-2025-46716
Sandboxie Arbitrary Kernel Read in SbieDrv.sys API (API_SET_SECURE_PARAM)
Published 2025-05-22 · Analyzed
5.5EPSS 0.002
CVE-2026-34527
Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrect nibble extraction
Published 2026-05-05 · Analyzed
5.3EPSS 0.001