Known Vulnerabilities for Cryptocat by Cryptocat Project

Listed below are 10 of the newest known vulnerabilities associated with "Cryptocat" by "Cryptocat Project".

These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.

Data on known vulnerable versions is also displayed based on information from known CPEs

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2013-4110 json Cryptocat has an Unspecified Chat Participant User List Disclosure 5.3 - MEDIUM 2019-11-05 2019-11-05
CVE-2013-4109 json An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165. 6.1 - MEDIUM 2019-11-14 2019-11-18
CVE-2013-4108 json Multiple unspecified vulnerabilities in Cryptocat Project Cryptocat 2.0.18 have unknown impact and attack vectors. 9.8 - CRITICAL 2019-11-14 2019-11-19
CVE-2013-4107 json Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting 6.1 - MEDIUM 2019-11-05 2019-11-05
CVE-2013-4106 json A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22. 6.1 - MEDIUM 2019-11-14 2019-11-18
CVE-2013-4105 json Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure 7.5 - HIGH 2019-11-04 2019-11-05
CVE-2013-4104 json Cryptocat before 2.0.22 has weak encryption in the Socialist Millionnaire Protocol 7.5 - HIGH 2019-11-04 2019-11-06
CVE-2013-4103 json Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input 9.8 - CRITICAL 2019-11-04 2019-11-06
CVE-2013-4102 json Cryptocat before 2.0.22 strophe.js Math.random() Random Number Generator Weakness 9.1 - CRITICAL 2019-11-04 2019-11-05
CVE-2013-4101 json Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness 5.3 - MEDIUM 2019-11-04 2019-11-08

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationCryptocat ProjectCryptocat3.2.08
ApplicationCryptocat ProjectCryptocat3.2.07
ApplicationCryptocat ProjectCryptocat3.2.06
ApplicationCryptocat ProjectCryptocat3.2.05
ApplicationCryptocat ProjectCryptocat3.2.04
ApplicationCryptocat ProjectCryptocat3.2.03
ApplicationCryptocat ProjectCryptocat3.2.02
ApplicationCryptocat ProjectCryptocat3.2.01
ApplicationCryptocat ProjectCryptocat3.2.00
ApplicationCryptocat ProjectCryptocat3.1.26
ApplicationCryptocat ProjectCryptocat3.1.25
ApplicationCryptocat ProjectCryptocat3.1.24
ApplicationCryptocat ProjectCryptocat3.1.23
ApplicationCryptocat ProjectCryptocat3.1.22
ApplicationCryptocat ProjectCryptocat3.1.21
ApplicationCryptocat ProjectCryptocat3.1.20
ApplicationCryptocat ProjectCryptocat3.1.19
ApplicationCryptocat ProjectCryptocat3.1.18
ApplicationCryptocat ProjectCryptocat3.1.17
ApplicationCryptocat ProjectCryptocat3.1.16

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report