Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gaizhenbiao

First CVE: Apr 10, 2024Active for: 2 yearsTotal CVEs: 31
45.9
VTI Score
High

Gaizhenbiao develops the ChuanhuChatGPT application, a web-based interface for interacting with large language models that has attracted significant attention in the vulnerability landscape. Vulnerabilities affecting this vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across input-handling and access-control boundaries including cross-site scripting, path traversal, improper resource throttling, and authorization flaws. The exposure reflects common risks in rapidly developed web applications that integrate external AI services and handle user input at scale, where insufficient validation and access controls can expose both application functionality and underlying model access to compromise. Defenders deploying or exposing this application should prioritize input validation hardening, rate-limiting mechanisms, and access-control audits; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
15.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gaizhenbiao over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2024
2 years ago
Most Recent CVE
Mar 20, 2025
495 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-3234CRITICAL
The gaizhenbiao/chuanhuchatgpt application is vulnerable to a path traversal attack due to its use of an outdated gradio component. The application is designed to restrict user acc
Jun 6, 20249.845NOYES
CVE-2024-5982CRITICAL
A path traversal vulnerability exists in the latest version of gaizhenbiao/chuanhuchatgpt. The vulnerability arises from unsanitized input handling in multiple features, including
Oct 29, 20249.843NONO
CVE-2024-6255CRITICAL
A vulnerability in the JSON file handling of gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to delete any JSON file on the server, including critical configuration fil
Jul 31, 20249.130NONO
CVE-2024-6037CRITICAL
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows an attacker to create arbitrary folders at any location on the server, including the root directory (C: dir).
Jul 10, 20249.129NONO
CVE-2024-6036CRITICAL
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240410 allows any user to restart the server at will by sending a specific request to the `/queue/join?` endpoint with `"fn_
Jul 10, 20249.129NONO
CVE-2024-5822CRITICAL
A Server-Side Request Forgery (SSRF) vulnerability exists in the upload processing interface of gaizhenbiao/ChuanhuChatGPT versions <= ChuanhuChatGPT-20240410-git.zip. This vulnera
Jun 27, 20249.829NONO
CVE-2024-5823CRITICAL
A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical co
Oct 29, 20249.124NONO
CVE-2024-8613HIGH
A vulnerability in gaizhenbiao/chuanhuchatgpt version 20240802 allows attackers to access, copy, and delete other users' chat histories. This issue arises due to improper handling
Mar 20, 20258.823NONO
CVE-2024-9216HIGH
An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability
Mar 20, 20258.122NONO
CVE-2024-6090HIGH
A path traversal vulnerability exists in gaizhenbiao/chuanhuchatgpt version 20240410, allowing any user to delete other users' chat histories. This vulnerability can also be exploi
Jun 27, 20247.522NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
42%
35%
23%
Severity distribution among all CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None25 (80.6%)
Unknown0 (0.0%)
Required6 (19.4%)
Privileges Required
Low12 (38.7%)
High0 (0.0%)
None19 (61.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.2% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gaizhenbiao.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gaizhenbiao — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gaizhenbiao's Products

View all 2 CNAs →

Top CWEs