Webchess Project maintains a focused web-based chess application where the durable signal centers on SQL injection vulnerabilities in database query construction. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webchess Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-22959HIGH WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName). | Jan 11, 2023 | 8.8 | 34 | NO | NO |
CVE-2019-20896CRITICAL WebChess 1.0 allows SQL injection via the messageFrom, gameID, opponent, messageID, or to parameter. | Jul 7, 2020 | 9.8 | 31 | NO | NO |
CVE-2023-39851CRITICAL webchess v1.0 was discovered to contain a SQL injection vulnerability via the $playerID parameter at mainmenu.php. NOTE: this is disputed by a third party who indicates that the pl | Aug 15, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webchess Project.
Media articles that mention a CVE ID that affects a product developed by Webchess Project — matched by CVE ID, not by vendor name.