Livehelperchat
Livehelperchat Live Helper Chat: vulnerabilidades y CVE
Livehelperchat Live Helper Chat tiene 40 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses3
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-44633 | Alta (8.1) | 0.38% | — | 14 may 2026 | Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they… |
| CVE-2026-27954 | Media (4.9) | 0.34% | — | 26 feb 2026 | Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat… |
| CVE-2026-0483 | Media (6.9) | 0.28% | — | 28 ene 2026 | Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be… |
| CVE-2025-51403 | Media (6.5) | 1.5% | — | 21 jul 2025 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into… |
| CVE-2025-51401 | Media (5.4) | 0.92% | — | 21 jul 2025 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name… |
| CVE-2025-51400 | Media (5.4) | 0.92% | — | 21 jul 2025 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. |
| CVE-2025-51398 | Media (5.4) | 0.92% | — | 21 jul 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name… |
| CVE-2025-51397 | Media (5.4) | 0.95% | — | 21 jul 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname… |
| CVE-2025-51396 | Media (5.4) | 0.97% | — | 21 jul 2025 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter. |
| CVE-2024-27516 | Crítica (9.8) | 1.5% | — | 29 feb 2024 | Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in… |
| CVE-2022-1530 | Media (6.1) | 0.65% | — | 29 abr 2022 | Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application. |
| CVE-2022-0935 | Alta (8.8) | 1.3% | — | 7 abr 2022 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. |
| CVE-2022-1234 | Media (6.1) | 0.73% | — | 6 abr 2022 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web… |
| CVE-2022-1235 | Alta (8.2) | 0.56% | — | 5 abr 2022 | Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-1213 | Alta (8.1) | 0.58% | — | 5 abr 2022 | SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191 |
| CVE-2022-1176 | Alta (7.5) | 1.3% | — | 31 mar 2022 | Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-1191 | Alta (8.1) | 0.95% | — | 31 mar 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. |
| CVE-2022-0612 | Media (5.4) | 0.61% | — | 16 feb 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0502 | Media (5.4) | 0.61% | — | 6 feb 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0395 | Media (5.4) | 0.64% | — | 28 ene 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0394 | Media (5.4) | 0.55% | — | 28 ene 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0375 | Media (4.8) | 0.70% | — | 26 ene 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0374 | Media (5.4) | 0.69% | — | 26 ene 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |
| CVE-2022-0266 | Media (6.6) | 1.1% | — | 19 ene 2022 | Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v. |
| CVE-2022-0226 | Media (4.3) | 0.43% | — | 14 ene 2022 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2022-0231 | Media (6.5) | 0.51% | — | 14 ene 2022 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) |
| CVE-2022-0083 | Media (5.3) | 0.90% | — | 4 ene 2022 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information |
| CVE-2021-4176 | Media (6.1) | 0.78% | — | 29 dic 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4175 | Media (5.4) | 0.53% | — | 29 dic 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
| CVE-2021-4179 | Media (5.4) | 0.46% | — | 28 dic 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.