Chatengine Project maintains a focused web-based communication platform whose vulnerability profile skews strongly toward critical-severity outcomes, reflecting the inherent risks of server-side web application logic handling user input and database queries. The recurring exposure centers on the core Chatengine product and clusters around foundational input-handling weaknesses: cross-site scripting and SQL injection, both of which are characteristic of web applications that process and reflect untrusted user-supplied data. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chatengine Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30319CRITICAL Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attack | Jul 6, 2023 | 9.6 | 25 | NO | NO |
CVE-2023-30321CRITICAL Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows att | Jul 6, 2023 | 9.0 | 24 | NO | NO |
CVE-2023-30320CRITICAL Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attac | Jul 6, 2023 | 9.0 | 24 | NO | NO |
CVE-2023-30325HIGH SQL Injection vulnerability in textMessage parameter in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine v.1.0, allows attackers to gain sensitive information. | Jul 6, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-30323HIGH SQL Injection vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to gain sensitive information. | Jul 6, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-30326MEDIUM Cross Site Scripting (XSS) vulnerability in username field in /WebContent/WEB-INF/lib/chatbox.jsp in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows atta | Jul 6, 2023 | 6.1 | 18 | NO | NO |
CVE-2023-30322MEDIUM Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to execute arbitrary code. | Jul 6, 2023 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chatengine Project.
Media articles that mention a CVE ID that affects a product developed by Chatengine Project — matched by CVE ID, not by vendor name.