Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bigantsoft

First CVE: Apr 22, 2008Active for: 18 yearsTotal CVEs: 17
56.4
VTI Score
TOP TARGET

Bigantsoft develops a focused line of enterprise messaging and collaboration server products including Bigant Server, Bigant IM Message Server, and Bigant Messenger, which serve as centralized communication platforms for business environments. The vendor's vulnerabilities recur around application-layer weaknesses including buffer-boundary violations, SQL injection, unrestricted file uploads, authentication bypass, and cross-site request forgery, reflecting the input-handling and access-control demands of web-facing messaging infrastructure; these issues have frequently acquired public exploit tooling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bigantsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2008
18 years ago
Most Recent CVE
Feb 4, 2025
536 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-1914HIGH
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows remote attackers to execute arbitrary code via a long URI in
Apr 22, 200810.081NOYES
CVE-2009-4660HIGH
Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to execute arbitrary code via a long GET request to TCP port 66
Mar 3, 201010.076NOYES
CVE-2012-6275HIGH
Multiple stack-based buffer overflows in AntDS.exe in BigAntSoft BigAnt IM Message Server allow remote attackers to have an unspecified impact via (1) the filename header in an SCH
Feb 24, 201310.074NOYES
CVE-2012-6274MEDIUM
BigAntSoft BigAnt IM Message Server does not require authentication for file uploading, which allows remote attackers to create arbitrary files under AntServer\DocData\Public via u
Feb 24, 20135.061NOYES
CVE-2022-23347HIGH
BigAnt Software BigAnt Server v5.6.06 was discovered to be vulnerable to directory traversal attacks.
Mar 21, 20227.536NOYES
CVE-2025-0364CRITICAL
BigAntSoft BigAnt Server, up to and including version 5.6.06, is vulnerable to unauthenticated remote code execution via account registration. An unauthenticated remote attacker ca
Feb 4, 20259.831NONO
CVE-2022-23346HIGH
BigAnt Software BigAnt Server v5.6.06 was discovered to contain incorrect access control issues.
Mar 21, 20228.831NONO
CVE-2024-54761MEDIUM
BigAnt Office Messenger 5.6.06 is vulnerable to SQL Injection via the 'dev_code' parameter.
Jan 9, 20256.328NOYES
CVE-2022-23352HIGH
An issue in BigAnt Software BigAnt Server v5.6.06 can lead to a Denial of Service (DoS).
Mar 21, 20227.528NONO
CVE-2021-43430HIGH
An Access Control vulnerability exists in BigAntSoft BigAnt office messenger 5.6 via im_webserver, which could let a malicious user upload PHP Trojan files.
Apr 7, 20228.827NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
29%
65%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (64.7%)
Unknown6 (35.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (64.7%)
High0 (0.0%)
Unknown6 (35.3%)
User Interaction
None8 (47.1%)
Unknown6 (35.3%)
Required3 (17.6%)
Privileges Required
Low3 (17.6%)
High0 (0.0%)
None8 (47.1%)
Unknown6 (35.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
4 CVEs
23.5% of CVEs· 99th percentile
Nuclei
2 CVEs
11.8% of CVEs· 96th percentile
ExploitDB
6 CVEs
35.3% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bigantsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bigantsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bigantsoft's Products

View all 3 CNAs →

Top CWEs