Douchat is a focused chat or messaging platform where the durable vulnerability signal centers on path-traversal and XML-entity-handling issues affecting file and document processing. These input-validation weaknesses are characteristic of applications handling untrusted file paths and external data sources; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Douchat over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-35324CRITICAL Douchat 4.0.5 suffers from an arbitrary file upload vulnerability via Public/Plugins/webuploader/server/preview.php. | May 28, 2024 | 9.8 | 27 | NO | NO |
CVE-2018-18737HIGH An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF. | Oct 29, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Douchat.
Media articles that mention a CVE ID that affects a product developed by Douchat — matched by CVE ID, not by vendor name.