Cbot develops a narrowly scoped chatbot platform comprising a core engine and administrative panel that, despite limited product breadth, carries disproportionate risk due to a persistent concentration of authentication and authorization weaknesses. Its vulnerability profile skews strongly toward critical-severity outcomes across recurring flaws in credential validation, token generation, message integrity, and origin validation—weaknesses endemic to session-management and WebSocket communication that undermine the security perimeter of systems relying on the platform. Defenders should prioritize patching and credential-rotation policies for deployments of this vendor's products; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cbot over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2887CRITICAL Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass.
This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7. | May 25, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-2882CRITICAL Generation of Incorrect Security Tokens vulnerability in CBOT Chatbot allows Token Impersonation, Privilege Abuse.
This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3. | May 25, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-2884CRITICAL Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG), Use of Insufficiently Random Values vulnerability in CBOT Chatbot allows Signature Spoofing by Key Recreation.
| May 25, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-2883HIGH Authorization Bypass Through User-Controlled Key vulnerability in CBOT Chatbot allows Authentication Abuse, Authentication Bypass.
This issue affects Chatbot: before Core: v4.0.3. | May 25, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-2885HIGH Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM).
This issue affects Ch | May 25, 2023 | 8.1 | 24 | NO | NO |
CVE-2023-2886MEDIUM Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation.
This issue affects Chatbot: before Core: v4.0.3.4 P | May 25, 2023 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cbot.
Media articles that mention a CVE ID that affects a product developed by Cbot — matched by CVE ID, not by vendor name.