Phpfreechat is a web-based chat application with a compact vulnerability footprint centered on its core chat product, where observed issues cluster around sensitive information exposure, authentication weaknesses, and uncontrolled resource consumption typical of real-time communication systems. Treat this as a narrow vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpfreechat over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5954HIGH phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands. | Jan 25, 2018 | 7.5 | 38 | NO | YES |
CVE-2011-3777MEDIUM phpFreeChat 1.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrate | Sep 24, 2011 | 5.0 | 17 | NO | NO |
CVE-2008-3428MEDIUM Session fixation vulnerability in phpFreeChat 1.1 allows remote authenticated users to hijack web sessions by setting the session_id parameter to match the victim's nickid paramete | Jul 31, 2008 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpfreechat.
Media articles that mention a CVE ID that affects a product developed by Phpfreechat — matched by CVE ID, not by vendor name.