Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gajim

First CVE: May 18, 2012Active for: 14 yearsTotal CVEs: 8

Gajim is an open-source instant-messaging client that has accumulated a modestly documented vulnerability history concentrated in its core application. Its recurring exposure centers on application-level input handling and access-control weaknesses, including improper input validation, code injection, and link-following issues that are typical of feature-rich desktop communication software. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gajim over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 18, 2012
14 years ago
Most Recent CVE
Sep 27, 2022
1,396 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41055HIGH
Gajim 1.2.x and 1.3.x before 1.3.3 allows remote attackers to cause a denial of service (crash) via a crafted XMPP Last Message Correction (XEP-0308) message in multi-user chat, wh
Oct 11, 20217.524NONO
CVE-2012-2086HIGH
SQL injection vulnerability in the get_last_conversation_lines function in common/logger.py in Gajim before 0.15 allows remote attackers to execute arbitrary SQL commands via the j
Nov 23, 20127.523NONO
CVE-2012-2085MEDIUM
The exec_command function in common/helpers.py in Gajim before 0.15 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in an href attribut
Aug 28, 20126.822NONO
CVE-2022-39835MEDIUM
An issue was discovered in Gajim through 1.4.7. The vulnerability allows attackers, via crafted XML stanzas, to correct messages that were not sent by them. The attacker needs to b
Sep 27, 20225.320NONO
CVE-2016-10376MEDIUM
Gajim through 0.16.7 unconditionally implements the "XEP-0146: Remote Controlling Clients" extension. This can be abused by malicious XMPP servers to, for example, extract plaintex
May 28, 20174.519NONO
CVE-2015-8688MEDIUM
Gajim before 0.16.5 allows remote attackers to modify the roster and intercept messages via a crafted roster-push IQ stanza.
Jan 15, 20165.417NONO
CVE-2012-5524MEDIUM
The _ssl_verify_callback function in tls_nb.py in Gajim before 0.15.3 does not properly verify SSL certificates, which allows remote attackers to conduct man-in-the-middle (MITM) a
Feb 8, 20144.317NONO
CVE-2012-2093LOW
src/common/latex.py in Gajim 0.15 allows local users to overwrite arbitrary files via a symlink attack on a temporary latex file, related to the get_tmpfile_name function.
May 18, 20123.316NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
13%
63%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network4 (50.0%)
Unknown4 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High0 (0.0%)
Unknown4 (50.0%)
User Interaction
None2 (25.0%)
Unknown4 (50.0%)
Required2 (25.0%)
Privileges Required
Low0 (0.0%)
High1 (12.5%)
None3 (37.5%)
Unknown4 (50.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gajim.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gajim — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gajim's Products

View all 2 CNAs →

Top CWEs