Cryptocat is a focused encrypted messaging application whose vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code. The exposure centers on a single product and recurs through weakness classes including information exposure, input validation flaws, and cross-site scripting—patterns typical of web-based communication platforms where session management, message handling, and client-side rendering present persistent attack surfaces. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cryptocat Project over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-4103CRITICAL Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input | Nov 4, 2019 | 9.8 | 37 | NO | YES |
CVE-2013-2261HIGH Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | Nov 4, 2019 | 7.5 | 33 | NO | YES |
CVE-2013-2259CRITICAL Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview | Nov 4, 2019 | 9.8 | 25 | NO | NO |
CVE-2013-4108CRITICAL Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors. | Nov 14, 2019 | 9.8 | 24 | NO | NO |
CVE-2013-2260CRITICAL Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness | Nov 4, 2019 | 9.8 | 24 | NO | NO |
CVE-2013-4102CRITICAL Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness | Nov 4, 2019 | 9.1 | 24 | NO | NO |
CVE-2013-2257HIGH Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness | Nov 4, 2019 | 7.5 | 20 | NO | NO |
CVE-2013-2262HIGH Cryptocat strophe.js before 2.0.22 has information disclosure | Nov 4, 2019 | 7.5 | 20 | NO | NO |
CVE-2013-4100HIGH Cryptocat before 2.0.22 has Remote Denial of Service via username | Nov 4, 2019 | 7.5 | 20 | NO | NO |
CVE-2013-4105HIGH Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure | Nov 4, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cryptocat Project.
Media articles that mention a CVE ID that affects a product developed by Cryptocat Project — matched by CVE ID, not by vendor name.