The Chaos Tool Suite Project maintains a specialized automation and testing framework that occupies a niche role in DevOps and chaos-engineering workflows, concentrating vulnerability exposure within a focused product line. Its disclosures recur through web-layer and code-generation weakness classes—cross-site scripting, cross-site request forgery, sensitive-information exposure, and code-injection flaws—typical of frameworks that process user input and generate or execute code dynamically. Defenders deploying this tool in CI/CD pipelines or testing environments should treat input sanitization and access controls as primary hardening points; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chaos Tool Suite Project over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1547MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to hijack the authentica | May 21, 2010 | 6.8 | 20 | NO | NO |
CVE-2015-7875HIGH ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems | Aug 7, 2017 | 7.5 | 19 | NO | NO |
CVE-2010-2010MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script | May 21, 2010 | 4.3 | 19 | NO | NO |
CVE-2010-1546MEDIUM Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with | May 21, 2010 | 6.0 | 19 | NO | NO |
CVE-2015-4398MEDIUM Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web | Jun 16, 2015 | 5.8 | 16 | NO | NO |
CVE-2015-6665MEDIUM Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject ar | Aug 24, 2015 | 4.3 | 14 | NO | NO |
CVE-2015-4375MEDIUM The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities wit | Jun 15, 2015 | 4.3 | 14 | NO | NO |
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated u | Dec 3, 2012 | 2.6 | 14 | NO | NO |
The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated use | May 21, 2010 | 3.5 | 14 | NO | NO |
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" per | Jul 16, 2013 | 3.5 | 13 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chaos Tool Suite Project.
Media articles that mention a CVE ID that affects a product developed by Chaos Tool Suite Project — matched by CVE ID, not by vendor name.