Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

1000mz

First CVE: Jan 6, 2025Active for: 2 yearsTotal CVEs: 11
44.4
VTI Score
High

1000mz maintains Chestnut CMS, a modestly represented content-management platform whose vulnerabilities skew toward serious outcomes and concentrate in file-handling and access-control weakness classes such as path traversal, unrestricted file uploads, improper access control, unsafe deserialization, and exposure of sensitive resources. These flaws are characteristic of web application codebases where user input validation and administrative boundary enforcement demand sustained attention. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
5.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by 1000mz over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 6, 2025
18 months ago
Most Recent CVE
Feb 5, 2026
170 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-15009HIGH
A flaw has been found in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function FilenameUtils.getExtension of the file /dev-api/common/upload of the component Fil
Dec 22, 20258.827NONO
CVE-2024-56828CRITICAL
File Upload vulnerability in ChestnutCMS through 1.5.0. Based on the code analysis, it was determined that the /api/member/avatar API endpoint receives a base64 string as input. Th
Jan 6, 20259.826NONO
CVE-2025-70073HIGH
An issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation function
Feb 5, 20267.225NONO
CVE-2024-57450CRITICAL
ChestnutCMS <=1.5.0 is vulnerable to File Upload via the Create template function.
Feb 3, 20259.825NONO
CVE-2025-5552HIGH
A vulnerability was found in ChestnutCMS up to 15.1. It has been declared as critical. This vulnerability affects unknown code of the file /dev-api/groovy/exec of the component API
Jun 4, 20258.824NONO
CVE-2025-2917HIGH
A vulnerability, which was classified as problematic, was found in ChestnutCMS up to 1.5.3. Affected is the function readFile of the file /dev-api/cms/file/read. The manipulation o
Mar 28, 20257.522NONO
CVE-2025-2031HIGH
A vulnerability classified as critical has been found in ChestnutCMS up to 1.5.2. This affects the function uploadFile of the file /dev-api/cms/file/upload. The manipulation of the
Mar 6, 20257.621NONO
CVE-2024-57451HIGH
ChestnutCMS <=1.5.0 has a directory traversal vulnerability in contentcore.controller.FileController#getFileList, which allows attackers to view any directory.
Feb 3, 20257.520NONO
CVE-2024-57452HIGH
ChestnutCMS <=1.5.0 has an arbitrary file deletion vulnerability in contentcore.controller.FileController, which allows attackers to delete any file and folder.
Feb 3, 20257.520NONO
CVE-2025-12923MEDIUM
A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownload of the file /dev-api/common/download. Executing manipula
Nov 10, 20254.919NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
9%
9%
64%
18%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (9.1%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low4 (36.4%)
High2 (18.2%)
None5 (45.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by 1000mz.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by 1000mz — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For 1000mz's Products

View all 2 CNAs →

Top CWEs