nextchat records
4 published records for vendor nextchat.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2023-49785Proof of concept | NextChat vulnerable to Server-Side Request Forgery and Cross-site Scriptingnextchat · nextchat · CWE-79 | Critical9.8 | — | 83.2% | Mar 11, 2024 |
30Monitor | CVE-2025-50735No exploit | Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in itsnextchat · nextchat · CWE-22 | High7.5 | — | 0.9% | Nov 3, 2025 |
22Monitor | CVE-2026-7177No exploit | ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgerynextchat · nextchat · CWE-918 | Medium5.5 | — | 0.6% | Apr 27, 2026 |
22Monitor | CVE-2026-7178No exploit | ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgerynextchat · nextchat · CWE-918 | Medium5.5 | — | 0.6% | Apr 27, 2026 |
- CVE-2023-4978564This week
NextChat vulnerable to Server-Side Request Forgery and Cross-site Scripting
CriticalCVSS 9.8Proof of conceptEPSS 83%nextchat · nextchatMar 11, 2024
- CVE-2025-5073530Monitor
Directory traversal vulnerability in NextChat thru 2.16.0 due to the WebDAV proxy failing to canonicalize or reject dot path segments in its
HighCVSS 7.5No exploitEPSS 1%nextchat · nextchatNov 3, 2025
- CVE-2026-717722Monitor
ChatGPTNextWeb NextChat route.ts proxyHandler server-side request forgery
MediumCVSS 5.5No exploitEPSS 1%nextchat · nextchatApr 27, 2026
- CVE-2026-717822Monitor
ChatGPTNextWeb NextChat Artifacts Endpoint route.ts storeUrl server-side request forgery
MediumCVSS 5.5No exploitEPSS 1%nextchat · nextchatApr 27, 2026