Chatelao
8 CVEs tracked since 2009. Since Jul 2009, none of them reached CISA KEV.
Chatelao CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2009-07 | 1 | 0 |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | null or fewer | |
| 2009-12 | null or fewer | |
| 2010-01 | null or fewer | |
| 2010-02 | null or fewer | |
| 2010-03 | null or fewer | |
| 2010-04 | null or fewer | |
| 2010-05 | null or fewer | |
| 2010-06 | null or fewer | |
| 2010-07 | null or fewer | |
| 2010-08 | null or fewer | |
| 2010-09 | null or fewer | |
| 2010-10 | null or fewer | |
| 2010-11 | null or fewer | |
| 2010-12 | null or fewer | |
| 2011-01 | null or fewer | |
| 2011-02 | null or fewer | |
| 2011-03 | null or fewer | |
| 2011-04 | null or fewer | |
| 2011-05 | null or fewer | |
| 2011-06 | null or fewer | |
| 2011-07 | null or fewer | |
| 2011-08 | null or fewer | |
| 2011-09 | null or fewer | |
| 2011-10 | null or fewer | |
| 2011-11 | null or fewer | |
| 2011-12 | null or fewer | |
| 2012-01 | null or fewer | |
| 2012-02 | null or fewer | |
| 2012-03 | null or fewer | |
| 2012-04 | null or fewer | |
| 2012-05 | 1 | 0 |
| 2012-06 | null or fewer | |
| 2012-07 | null or fewer | |
| 2012-08 | null or fewer | |
| 2012-09 | 2 | 0 |
| 2012-10 | null or fewer | |
| 2012-11 | null or fewer | |
| 2012-12 | null or fewer | |
| 2013-01 | null or fewer | |
| 2013-02 | null or fewer | |
| 2013-03 | null or fewer | |
| 2013-04 | 4 | 0 |
Products
The products that kept showing up in Chatelao's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 9 most recently published vulnerabilities affecting Chatelao.
- CVE-2020-37083addressbook 9.0.0.1 - 'id' SQL Injection8.2
- CVE-2013-1748Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the vi...7.5
- CVE-2013-1749Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via the Address field.4.3
- CVE-2013-2778Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack the authentication of administrators for requests...7.5
- CVE-2013-0135Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addre...7.5
- CVE-2012-1911Multiple SQL injection vulnerabilities in PHP Address Book 6.2.12 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) to_group parameter to group.php or (2) id paramete...7.5
- CVE-2012-1912Cross-site scripting (XSS) vulnerability in preferences.php in PHP Address Book 7.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the from parameter. NOTE: the ind...4.3
- CVE-2012-2903Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 7.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO to group.php, or the (2) ...4.3
- CVE-2009-2608Multiple SQL injection vulnerabilities in PHP Address Book 4.0.x allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to delete.php or (2) alphabet parameter to index.p...6.8
The record
- Peak rank
- #22 in Apr 2013
- Busiest month shown
- Apr 2013, 4 CVEs
- Months with a KEV entry
- 0 since Jul 2009
- Monthly snapshots
- 4 since 2009