Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Chaos Tool Suite Project

First CVE: May 21, 2010Active for: 16 yearsTotal CVEs: 11
17.8
VTI Score
Low

The Chaos Tool Suite Project maintains a specialized automation and testing framework that occupies a niche role in DevOps and chaos-engineering workflows, concentrating vulnerability exposure within a focused product line. Its disclosures recur through web-layer and code-generation weakness classes—cross-site scripting, cross-site request forgery, sensitive-information exposure, and code-injection flaws—typical of frameworks that process user input and generate or execute code dynamically. Defenders deploying this tool in CI/CD pipelines or testing environments should treat input sanitization and access controls as primary hardening points; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
4.6
Avg CVSS Score
Higher Avg CVSS Score than 7% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Chaos Tool Suite Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 21, 2010
16 years ago
Most Recent CVE
Aug 7, 2017
3,277 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2010-1547MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to hijack the authentica
May 21, 20106.820NONO
CVE-2015-7875HIGH
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems
Aug 7, 20177.519NONO
CVE-2010-2010MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote attackers to inject arbitrary web script
May 21, 20104.319NONO
CVE-2010-1546MEDIUM
Multiple eval injection vulnerabilities in the import functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal allow remote authenticated users, with
May 21, 20106.019NONO
CVE-2015-4398MEDIUM
Open redirect vulnerability in the Chaos tool suite (ctools) module before 6.x-1.12 and 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to redirect users to arbitrary web
Jun 16, 20155.816NONO
CVE-2015-6665MEDIUM
Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject ar
Aug 24, 20154.314NONO
CVE-2015-4375MEDIUM
The Chaos tool suite (ctools) module 7.x-1.x before 7.x-1.7 for Drupal allows remote attackers to obtain sensitive node titles via (1) an autocomplete search on custom entities wit
Jun 15, 20154.314NONO
CVE-2012-5559LOW
Cross-site scripting (XSS) vulnerability in the page manager node view task in the Chaos tool suite (ctools) module 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated u
Dec 3, 20122.614NONO
CVE-2010-1548LOW
The auto-complete functionality in the Chaos Tool Suite (aka CTools) module 6.x before 6.x-1.4 for Drupal does not follow access restrictions, which allows remote authenticated use
May 21, 20103.514NONO
CVE-2013-1925LOW
The Chaos Tool Suite (ctools) module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict node access, which allows remote authenticated users with the "access content" per
Jul 16, 20133.513NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
36%
55%
9%
Severity distribution among all CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network1 (9.1%)
Unknown10 (90.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (9.1%)
High0 (0.0%)
Unknown10 (90.9%)
User Interaction
None1 (9.1%)
Unknown10 (90.9%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (9.1%)
Unknown10 (90.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Chaos Tool Suite Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Chaos Tool Suite Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Chaos Tool Suite Project's Products

View all 2 CNAs →

Top CWEs