Chevereto
2 CVEs tracked since 2012. Since May 2012, none of them reached CISA KEV.
Chevereto CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2012-05 | 2 | 0 |
Products
The products that kept showing up in Chevereto's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 6 most recently published vulnerabilities affecting Chevereto.
- CVE-2026-55417Chevereto private profile setting leaks username on /json endpoint—
- CVE-2021-31721Chevereto before 3.17.1 allows Cross Site Scripting (XSS) via an image title at the image upload stage.6.1
- CVE-2018-12030Chevereto Free before 1.0.13 has XSS.5.4
- CVE-2017-1000058Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.6.1
- CVE-2012-2918Cross-site scripting (XSS) vulnerability in Upload/engine.php in Chevereto 1.91 allows remote attackers to inject arbitrary web script or HTML via the v parameter.4.3
- CVE-2012-2919Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the existence of arbitrary files via a .. (dot dot) in the v parameter.5.0
The record
- Peak rank
- #39 in May 2012
- Busiest month shown
- May 2012, 2 CVEs
- Months with a KEV entry
- 0 since May 2012
- Monthly snapshots
- 1 since 2012