The Profanity Project maintains a focused software product centered on input filtering and content moderation, with observed vulnerability patterns concentrated on validation and cryptographic mechanisms. Its durable signal reflects the inherent risk in parsing and filtering logic: improper input validation, origin validation errors, and weak pseudo-random number generation recur as the primary weakness classes. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Profanity Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40769HIGH profanity through 1.60 has only four billion possible RNG initializations. Thus, attackers can recover private keys from Ethereum vanity addresses and steal cryptocurrency, as expl | Sep 18, 2022 | 7.5 | 26 | NO | NO |
CVE-2017-5592MEDIUM An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable applicat | Feb 9, 2017 | 5.9 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Profanity Project.
Media articles that mention a CVE ID that affects a product developed by Profanity Project — matched by CVE ID, not by vendor name.