Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
40 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.91% | — | 3CX Live Chat | 22/8/2019 | 17/6/2026 | The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections. | |
| Modificada | Media (6.1) | 0.92% | — | 3CX Live Chat | 13/8/2019 | 17/6/2026 | The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.2% | — | 3CX Live Chat | 12/8/2019 | 17/6/2026 | The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page. | |
| Modificada | Media (6.1) | 0.93% | — | 3CX Live Chat | 12/8/2019 | 17/6/2026 | The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS. | |
| Modificada | Media (6.1) | 0.93% | — | 3CX Live Chat | 12/8/2019 | 17/6/2026 | The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS. | |
| Modificada | Crítica (9.8) | 4.3% | — | 3CX Live Chat | 3/6/2019 | 17/6/2026 | The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete patch for CVE-2018-12426. Arbitrary file upload is achieved by using a non-blacklisted executable file extension in conjunction with a whitelisted file extension, and… | |
| Modificada | Media (6.1) | 1.4% | — | 3CX Live Chat | 22/3/2019 | 17/6/2026 | The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS. | |
| Modificada | Media (6.1) | 1.0% | — | 3CX Live Chat | 18/10/2018 | 17/6/2026 | XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request. | |
| Modificada | Crítica (9.8) | 5.1% | — | 3CX Live Chat | 2/7/2018 | 17/6/2026 | The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jpeg content type. | |
| Modificada | Media (6.1) | 1.1% | — | 3CX Live Chat | 15/5/2018 | 17/6/2026 | There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka wplc_email) input fields to wp-json/wp_live_chat_support/v1/start_chat whenever a malicious attacker would initiate a new chat with an administrator. NOTE: this issue… | |
| Modificada | Media (6.1) | 1.3% | — | 3CX Live Chat | 9/4/2018 | 17/6/2026 | The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field. | |
| Modificada | Media (6.1) | 1.3% | — | 3CX Live Chat | 9/6/2017 | 17/6/2026 | Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 1.2% | — | Acobot Live Chat & Contact Form Project Acobot Live Chat & Contact Form | 20/2/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Acobot Live Chat & Contact Form plugin 2.0 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or (2) conduct cross-site scripting (XSS) attacks via the acobot_token parameter… | |
| Modificada | Media (4.3) | 4.6% | — | Activehelper Livehelp Live Chat | 1/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in server/offline.php in the ActiveHelper LiveHelp Live Chat plugin 3.1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) MESSAGE, (2) EMAIL, or (3) NAME parameter. | |
| Modificada | Media (4.3) | 10% | — | Clickdesk Live Support-live Chat Plugin | 20/9/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in clickdesk.php in ClickDesk Live Support - Live Chat plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the cdwidgetid parameter. NOTE: some of these details are obtained from third party information. |