Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Chadhaajay

First CVE: Mar 12, 2020Active for: 6 yearsTotal CVEs: 119
34.2
VTI Score
Medium

Chadhaajay's vulnerability footprint centers on PHPKB, a knowledge-base and documentation platform widely deployed in enterprise and support environments, where the cumulative disclosure count reflects the application's exposure as a web-facing asset handling user input and administrative functions. The recurring weakness classes—cross-site scripting, cross-site request forgery, path traversal, code injection, and CSV formula injection—are characteristic of web application input handling and output encoding challenges endemic to this product category. Defenders should prioritize input and output validation controls on PHPKB instances and treat this vendor's patches as routine security maintenance for internet-reachable knowledge-base infrastructure. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
119
Total CVEs
More Total CVEs than 99% of tracked vendors
119.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
4.9
Avg CVSS Score
Higher Avg CVSS Score than 10% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Chadhaajay over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2020
6 years ago
Most Recent CVE
Sep 3, 2020
2,152 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (119 CVEs).

119 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-10386HIGH
admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory.
Mar 12, 20207.233NOYES
CVE-2020-11579HIGH
An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclos
Sep 3, 20207.532NONO
CVE-2020-10387MEDIUM
Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via th
Mar 12, 20204.930NOYES
CVE-2020-10390HIGH
OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code
Mar 12, 20207.224NONO
CVE-2020-10478HIGH
CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial o
Mar 12, 20208.822NONO
CVE-2020-10501MEDIUM
CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request.
Mar 12, 20206.521NONO
CVE-2020-10458MEDIUM
Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence (
Mar 12, 20206.520NONO
CVE-2020-10389HIGH
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global
Mar 12, 20207.220NONO
CVE-2020-10487MEDIUM
CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request.
Mar 12, 20204.318NONO
CVE-2020-10483MEDIUM
CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request.
Mar 12, 20204.318NONO
View all 119 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products119 CVEs
94%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network119 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (7.6%)
Unknown0 (0.0%)
Required110 (92.4%)
Privileges Required
Low1 (0.8%)
High89 (74.8%)
None29 (24.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (119 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.7% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Chadhaajay.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Chadhaajay — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Chadhaajay's Products

View all 1 CNAs →

Top CWEs