V3chat develops a suite of communication and dating-platform products, including instant messaging and live-support applications, with a vulnerability profile centered on web-application and authentication-layer weaknesses. The recurring exposure reflects characteristic input-handling and session-management gaps, spanning SQL injection, improper authentication mechanisms, and inadequate cookie validation across its product line.
The number and severity of CVEs published that impact products developed by V3chat over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5784CRITICAL V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | Dec 31, 2008 | 9.8 | 37 | NO | YES |
CVE-2008-5783HIGH admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1. | Dec 31, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-5785HIGH SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | Dec 31, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-6995MEDIUM mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername parameter. | Feb 12, 2007 | 6.0 | 25 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, | Jul 6, 2006 | 2.6 | 18 | NO | YES |
V3 Chat allows remote attackers to obtain the installation path via (1) an invalid id parameter to mail/index.php or (2) membername parameter to messenger/online.php, which display | Jul 6, 2006 | 2.6 | 12 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by V3chat.
Media articles that mention a CVE ID that affects a product developed by V3chat — matched by CVE ID, not by vendor name.