This page aggregates publicly disclosed CVE and security risk information related to chaozz, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2009-1053 | chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | [email protected] | 5.0 | 0.23% | 2009-03-24 | 2026-04-23 |
| CVE-2009-1052 | FireAnt 1.3 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | [email protected] | 5.0 | 0.28% | 2009-03-24 | 2026-04-23 |
| CVE-2009-1051 | FubarForum 1.6 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | [email protected] | 5.0 | 0.28% | 2009-03-24 | 2026-04-23 |