Vulnerabilities > Convos

DATE CVE VULNERABILITY TITLE RISK
2022-01-04 CVE-2022-21649 Cross-site Scripting vulnerability in Convos
Convos is an open source multi-user chat that runs in a web browser.
network
convos CWE-79
3.5
2022-01-04 CVE-2022-21650 Cross-site Scripting vulnerability in Convos
Convos is an open source multi-user chat that runs in a web browser.
network
convos CWE-79
3.5
2021-12-17 CVE-2021-42584 Cross-site Scripting vulnerability in Convos
A Stored Cross Site Scripting (XSS) issue exists in Convos-Chat before 6.32.
network
convos CWE-79
3.5
2020-06-18 CVE-2020-14423 Use of Insufficiently Random Values vulnerability in Convos
Convos before 4.20 does not properly generate a random secret in Core/Settings.pm and Util.pm.
network
low complexity
convos CWE-330
5.0