Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Weechat

First CVE: Apr 23, 2017Active for: 9 yearsTotal CVEs: 7

Weechat is a niche internet relay chat (IRC) client with a modest plugin ecosystem centered on the core application and its logger module, presenting a focused but specialized attack surface for users who rely on this messaging platform. Its vulnerabilities skew strongly toward critical-severity outcomes and recur through memory-safety and validation weaknesses, including classic buffer overflows, out-of-bounds reads, integer overflows, and improper certificate validation, reflecting the C codebase's exposure to untrusted network input and parsing complexity. Defenders who deploy or maintain Weechat should treat critical disclosures as high-priority given the severity tendency; live exploitation activity and current exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Weechat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 23, 2017
9 years ago
Most Recent CVE
Nov 10, 2024
621 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-8955CRITICAL
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly ha
Feb 12, 20209.831NONO
CVE-2024-46613CRITICAL
WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_spli
Nov 10, 20249.830NONO
CVE-2017-8073HIGH
WeeChat before 1.7.1 allows a remote crash by sending a filename via DCC to the IRC plugin. This occurs in the irc_ctcp_dcc_filename_without_quotes function during quote removal, w
Apr 23, 20177.526NONO
CVE-2021-40516HIGH
WeeChat before 3.2.1 allows remote attackers to cause a denial of service (crash) via a crafted WebSocket frame that trigger an out-of-bounds read in plugins/relay/relay-websocket.
Sep 5, 20217.525NONO
CVE-2017-14727HIGH
logger.c in the logger plugin in WeeChat before 1.9.1 allows a crash via strftime date/time specifiers, because a buffer is not initialized.
Sep 23, 20177.525NONO
CVE-2020-9760CRITICAL
An issue was discovered in WeeChat before 2.7.1 (0.3.4 to 2.7 are affected). When a new IRC message 005 is received with longer nick prefixes, a buffer overflow and possibly a cras
Mar 23, 20209.824NONO
CVE-2022-28352MEDIUM
WeeChat (aka Wee Enhanced Environment for Chat) 3.2 to 3.4 before 3.4.1 does not properly verify the TLS certificate of the server, after certain GnuTLS options are changed, which
Apr 2, 20224.819NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
14%
43%
43%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Weechat.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Weechat — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Weechat's Products

View all 1 CNAs →

Top CWEs