CVE-2025-26776: Notfound Chaty Pro

Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.

Unrestricted Upload of File with Dangerous Type vulnerability in NotFound Chaty Pro allows Upload a Web Shell to a Web Server. This issue affects Chaty Pro: from n/a through 3.3.3.

Affected products

  • Notfound Chaty Pro: up to and including 3.3.3

Published 2025-02-22. Last modified 2026-06-17.