Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1144 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | AYS AI Chatbot With Chatgpt AND Content GeneratorAI | 3/3/2026 | 17/6/2026 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the store_data() and get_chatgpt_api_key() functions in all versions up to, and including, 2.7.5. This makes it possible for unauthenticated… | |
| Analizada | Media (4.9) | 0.34% | — | Livehelperchat Live Helper Chat | 26/2/2026 | 17/6/2026 | Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats… | |
| Aplazada | Media (5.3) | 0.34% | — | Plugin-planet Simple Ajax ChatAI | 23/2/2026 | 17/6/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Jeff Starr Simple Ajax Chat simple-ajax-chat allows Retrieve Embedded Sensitive Data.This issue affects Simple Ajax Chat: from n/a through <= 20251121. | |
| Aplazada | Media (6.5) | 0.26% | — | Cliengo ChatbotAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in cliengo Cliengo – Chatbot cliengo allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4. | |
| Aplazada | Media (6.5) | 0.40% | — | Ahachat Messenger MarketingAI | 20/2/2026 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ahachat AhaChat Messenger Marketing ahachat-messenger-marketing allows Password Recovery Exploitation.This issue affects AhaChat Messenger Marketing: from n/a through <= 1.1. | |
| Aplazada | Media (5.3) | 0.22% | — | Ays-chatgpt-assistantAI | 19/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Ays Pro AI ChatBot with ChatGPT and Content Generator by AYS ays-chatgpt-assistant allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AI ChatBot with ChatGPT and Content Generator by AYS: from n/a through <= 2.7.4. | |
| Aplazada | Baja (2.7) | 0.33% | — | Oneclick Chat TO OrderAI | 19/2/2026 | 17/6/2026 | The OneClick Chat to Order plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.0.9. This is due to the plugin not properly verifying that a user is authorized to perform an action in the wa_order_number_save_number_field function. This makes it possible for authenticated… | |
| Aplazada | Media (6.4) | 0.27% | — | Collect.chat Chatbot FOR WordpressAI | 14/2/2026 | 17/6/2026 | The Chatbot for WordPress by Collect.chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_inpost_head_script[synth_header_script]' post meta field in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Aplazada | Media (5.3) | 0.36% | 💥 PoC | Wpguppy ONE TO ONE User ChatAI | 14/2/2026 | 17/6/2026 | The One to one user Chat by WPGuppy plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/guppylite/v2/channel-authorize rest endpoint in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to intercept and view… | |
| Aplazada | Media (5.1) | 0.20% | — | Business Live Chat SoftwareAI | 7/2/2026 | 17/6/2026 | Business Live Chat Software 1.0 contains a cross-site request forgery vulnerability that allows attackers to change user account roles without authentication. Attackers can craft a malicious HTML form to modify user privileges by submitting a POST request to the user creation endpoint with administrative access… | |
| Analizada | Alta (8.8) | 0.45% | — | Ciprianmp Phpmychat-plus | 5/2/2026 | 17/6/2026 | phpMyChat Plus 1.98 contains a SQL injection vulnerability in the deluser.php page through the pmc_username parameter that allows attackers to manipulate database queries. Attackers can exploit boolean-based, error-based, and time-based blind SQL injection techniques to extract sensitive database information by… | |
| Aplazada | Alta (7.1) | 0.38% | — | Nice ChatAI | 3/2/2026 | 17/6/2026 | HTML injection vulnerability in NICE Chat. This vulnerability allows an attacker to inject and render arbitrary HTML content in email transcripts by modifying the 'firstName' and 'lastName' parameters during a chat session. The injected HTML is included in the body of the email sent by the system, which could enable… | |
| Analizada | Crítica (9.8) | 1.5% | — | Wildfirechat Im-server | 2/2/2026 | 17/6/2026 | Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists in the im-server component related to the file upload functionality found in com.xiaoleilu.loServer.action.UploadFileAction. The application exposes an endpoint (/fs) that handles multipart file… | |
| Aplazada | Media (5.7) | 0.31% | — | LibrechatAI | 2/2/2026 | 17/6/2026 | A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents rapidly. If the forked content includes a Mermaid graph with a large number of nodes, it can lead to a JavaScript heap out of memory error upon service restart, causing a… | |
| Aplazada | Media (6.9) | 0.28% | — | Livehelperchat Live Helper ChatAI | 28/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the… | |
| Analizada | Media (5.4) | 0.34% | — | Chattermate | 24/1/2026 | 17/6/2026 | ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads when supplied as chat input. Specifically, an <iframe> payload containing a javascript: URI can be processed and executed in the browser context. This allows access to… | |
| Aplazada | Media (6.5) | 0.19% | — | Micro.company Form TO ChatAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Micro.company Form to Chat App form-to-chat allows Stored XSS.This issue affects Form to Chat App: from n/a through <= 1.2.5. | |
| Analizada | Media (5.7) | 0.23% | — | Crawlchat | 19/1/2026 | 17/6/2026 | CrawlChat is an open-source, AI-powered platform that transforms technical documentation into intelligent chatbots. Prior to version 0.0.8, a non-existing permission check for the CrawlChat's Discord bot allows non-manage guild users to put malicious content onto the collection knowledge base. Usually, admin / mods of… | |
| Analizada | Alta (7.5) | 0.55% | 💥 PoC | Chatterbot | 19/1/2026 | 17/6/2026 | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. ChatterBot versions up to 1.2.10 are vulnerable to a denial-of-service condition caused by improper database session and connection pool management. Concurrent invocations of the get_response() method can exhaust the underlying… | |
| Aplazada | Baja (3.7) | 0.23% | — | LobechatAI | 19/1/2026 | 17/6/2026 | LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filter in the database query is commented out, so it's enabling attackers… | |
| Aplazada | Media (6.4) | 0.14% | — | LobechatAI | 18/1/2026 | 17/6/2026 | LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Execution (RCE) by… | |
| Analizada | Media (6.5) | 0.35% | — | Rocket.chat | 14/1/2026 | 17/6/2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. In Rocket.Chat versions up to 6.12.0, the API endpoint GET /api/v1/oauth-apps.get is exposed to any authenticated user, regardless of their role or permissions. This endpoint returns an OAuth application, as long as the user knows its… | |
| Analizada | Crítica (9.9) | 4.1% | — | Librechat | 12/1/2026 | 17/6/2026 | LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2. | |
| Analizada | Alta (8.1) | 4.2% | — | Librechat | 7/1/2026 | 7/10/2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact… | |
| Analizada | Media (4.3) | 0.29% | — | Librechat | 7/1/2026 | 7/10/2026 | LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no permissions for this agent. LibreChat allows the configuration of agents that… |