Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.54%—Kognetiks Chatbot13/11/202417/6/2026
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to…
AplazadaMedia (6.1)0.34%—Aiml ChatbotAI25/10/202417/6/2026
AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts.
AnalizadaMedia (5.3)1.1%—Webdigit Chatbot With Chatgpt25/9/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key
AnalizadaMedia (5.3)1.3%—Webdigit Chatbot With Chatgpt5/9/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs
AnalizadaMedia (4.8)0.31%—Mansurahamed Chatbot Support AI4/9/202417/6/2026
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…
AnalizadaCrítica (9.8)0.74%—Webdigit Chatbot With Chatgpt20/8/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
AnalizadaMedia (6.1)0.41%—Webdigit Chatbot With Chatgpt19/8/202417/6/2026
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins
AplazadaMedia (5.4)0.18%—Cliengo ChatbotAI9/7/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4.
ModificadaMedia (5.4)0.25%—Kognetics Kognetiks Chatbot8/6/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kognetiks Kognetiks Chatbot for WordPress allows Stored XSS.This issue affects Kognetiks Chatbot for WordPress: from n/a through 1.9.8.
AplazadaCrítica (9.8)0.91%—Kognetiks ChatbotAI14/5/202417/6/2026
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files…
AplazadaCrítica (10)2.6%—Kognetiks ChatbotAI14/5/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.
AplazadaMedia (6.5)0.35%—Quantumcloud Conversational Forms FOR ChatbotAI6/5/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.
AplazadaMedia (5.4)0.35%—Healthcare-chatbotAI15/3/202417/6/2026
A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php.
AplazadaAlta (7.1)0.46%—Student Information ChatbotAI11/3/202417/6/2026
Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php.
ModificadaMedia (4.8)0.29%—Collect.chat Chatbot11/1/202417/6/2026
The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts…
ModificadaMedia (4.8)0.39%—Quantumcloud Conversational Forms FOR Chatbot6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions.
ModificadaAlta (8.8)0.26%—Quantumcloud Chatbot23/2/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.
ModificadaCrítica (9.3)1.3%—Kg-fashion-chatbot Project Kg-fashion-chatbot11/7/202217/6/2026
The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaAlta (7.2)1.0%—Chatbot APP With Suggestion Project Chatbot APP With Suggestion2/6/202217/6/2026
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/view_response&id=.
ModificadaAlta (7.2)1.0%—Chatbot APP With Suggestion Project Chatbot APP With Suggestion2/6/202217/6/2026
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/manage_response&id=.
ModificadaCrítica (9.8)1.1%—Chatbot APP With Suggestion Project Chatbot APP With Suggestion2/6/202217/6/2026
ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=.
ModificadaMedia (6.5)0.98%—Chatbot APP With Suggestion Project Chatbot APP With Suggestion2/6/202217/6/2026
ChatBot App with Suggestion v1.0 is vulnerable to Delete any file via /simple_chat_bot/classes/Master.php?f=delete_img.
ModificadaMedia (5.4)0.50%—Chatbot APP With Suggestion Project Chatbot APP With Suggestion24/5/202217/6/2026
ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to Cross Site Scripting (XSS) via /simple_chat_bot/classes/Master.php?f=save_response.
ModificadaAlta (8.8)0.97%—Chatbot APP With Suggestion Project Chatbot APP With Suggestion24/5/202217/6/2026
ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id.
ModificadaCrítica (9.8)1.8%—Chatbot Application With A Suggestion Feature Project Chatbot Application With A Suggestion Feature20/5/202217/6/2026
ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php.