Chevereto is a niche image-hosting and gallery platform whose vulnerability disclosures center on its web application product and recur around input-handling weaknesses such as cross-site scripting and path traversal. These weakness classes are typical of web applications with complex file-management and user-input processing requirements. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chevereto over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2919MEDIUM Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the v paramete | May 21, 2012 | 5.0 | 27 | NO | YES |
CVE-2012-2918MEDIUM Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter. | May 21, 2012 | 4.3 | 25 | NO | YES |
CVE-2021-31721MEDIUM Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage. | Jun 30, 2021 | 6.1 | 23 | NO | NO |
CVE-2018-12030MEDIUM Chevereto Free before 1.0.13 has XSS. | Jun 15, 2018 | 5.4 | 18 | NO | NO |
CVE-2017-1000058MEDIUM Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser. | Jul 17, 2017 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chevereto.
Media articles that mention a CVE ID that affects a product developed by Chevereto — matched by CVE ID, not by vendor name.