Convos is a web-based chat and messaging platform with a compact vulnerability footprint centered on its core application. The observed weakness classes reflect application-layer risks common to web interfaces: cross-site scripting from improper input neutralization and weak random-value generation in security-sensitive contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Convos over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42584MEDIUM A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32. | Dec 17, 2021 | 5.4 | 21 | NO | NO |
CVE-2022-21650MEDIUM Convos is an open source multi-user chat that runs in a web browser. You can't use SVG extension in Convos' chat window, but you can upload a file with an .html extension. By uploa | Jan 4, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-21649MEDIUM Convos is an open source multi-user chat that runs in a web browser. Characters starting with "https://" in the chat window create an <a> tag. Stored XSS vulnerability using onfocu | Jan 4, 2022 | 5.4 | 16 | NO | NO |
CVE-2020-14423MEDIUM Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm. This leads to a predictable CONVOS_LOCAL_SECRET value, affecting password resets and | Jun 18, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Convos.
Media articles that mention a CVE ID that affects a product developed by Convos — matched by CVE ID, not by vendor name.