Chadhaajay's vulnerability footprint centers on PHPKB, a knowledge-base and documentation platform widely deployed in enterprise and support environments, where the cumulative disclosure count reflects the application's exposure as a web-facing asset handling user input and administrative functions. The recurring weakness classes—cross-site scripting, cross-site request forgery, path traversal, code injection, and CSV formula injection—are characteristic of web application input handling and output encoding challenges endemic to this product category. Defenders should prioritize input and output validation controls on PHPKB instances and treat this vendor's patches as routine security maintenance for internet-reachable knowledge-base infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chadhaajay over time
Signals from CVEs in this vendor scope (119 CVEs).
119 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10386HIGH admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory. | Mar 12, 2020 | 7.2 | 33 | NO | YES |
CVE-2020-11579HIGH An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclos | Sep 3, 2020 | 7.5 | 32 | NO | NO |
CVE-2020-10387MEDIUM Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via th | Mar 12, 2020 | 4.9 | 30 | NO | YES |
CVE-2020-10390HIGH OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code | Mar 12, 2020 | 7.2 | 24 | NO | NO |
CVE-2020-10478HIGH CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial o | Mar 12, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-10501MEDIUM CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request. | Mar 12, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-10458MEDIUM Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence ( | Mar 12, 2020 | 6.5 | 20 | NO | NO |
CVE-2020-10389HIGH admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global | Mar 12, 2020 | 7.2 | 20 | NO | NO |
CVE-2020-10487MEDIUM CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request. | Mar 12, 2020 | 4.3 | 18 | NO | NO |
CVE-2020-10483MEDIUM CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request. | Mar 12, 2020 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (119 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chadhaajay.
Media articles that mention a CVE ID that affects a product developed by Chadhaajay — matched by CVE ID, not by vendor name.