Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.54% | — | Kognetiks Chatbot | 13/11/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level access and above, to… | |
| Aplazada | Media (6.1) | 0.34% | — | Aiml ChatbotAI | 25/10/2024 | 17/6/2026 | AIML Chatbot 1.0 (fixed in 2.0) is vulnerable to Cross Site Scripting (XSS). The vulnerability is exploited through the message input field, where attackers can inject malicious HTML or JavaScript code. The chatbot fails to sanitize these inputs, leading to the execution of malicious scripts. | |
| Analizada | Media (5.3) | 1.1% | — | Webdigit Chatbot With Chatgpt | 25/9/2024 | 17/6/2026 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key | |
| Analizada | Media (5.3) | 1.3% | — | Webdigit Chatbot With Chatgpt | 5/9/2024 | 17/6/2026 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs | |
| Analizada | Media (4.8) | 0.31% | — | Mansurahamed Chatbot Support AI | 4/9/2024 | 17/6/2026 | The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in… | |
| Analizada | Crítica (9.8) | 0.74% | — | Webdigit Chatbot With Chatgpt | 20/8/2024 | 17/6/2026 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot. | |
| Analizada | Media (6.1) | 0.41% | — | Webdigit Chatbot With Chatgpt | 19/8/2024 | 17/6/2026 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins | |
| Aplazada | Media (5.4) | 0.18% | — | Cliengo ChatbotAI | 9/7/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cliengo Cliengo – Chatbot cliengo allows Cross Site Request Forgery.This issue affects Cliengo – Chatbot: from n/a through <= 3.0.4. | |
| Modificada | Media (5.4) | 0.25% | — | Kognetics Kognetiks Chatbot | 8/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kognetiks Kognetiks Chatbot for WordPress allows Stored XSS.This issue affects Kognetiks Chatbot for WordPress: from n/a through 1.9.8. | |
| Aplazada | Crítica (9.8) | 0.91% | — | Kognetiks ChatbotAI | 14/5/2024 | 17/6/2026 | The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the chatbot_chatgpt_upload_file_to_assistant function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers, with to upload arbitrary files… | |
| Aplazada | Crítica (10) | 2.6% | — | Kognetiks ChatbotAI | 14/5/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0. | |
| Aplazada | Media (6.5) | 0.35% | — | Quantumcloud Conversational Forms FOR ChatbotAI | 6/5/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0. | |
| Aplazada | Media (5.4) | 0.35% | — | Healthcare-chatbotAI | 15/3/2024 | 17/6/2026 | A Cross Site Scripting vulnerability in Healthcare-Chatbot through 9b7058a can occur via a crafted payload to the email1 or pwd1 parameter in login.php. | |
| Aplazada | Alta (7.1) | 0.46% | — | Student Information ChatbotAI | 11/3/2024 | 17/6/2026 | Student Information Chatbot a0196ab allows SQL injection via the username to the login function in index.php. | |
| Modificada | Media (4.8) | 0.29% | — | Collect.chat Chatbot | 11/1/2024 | 17/6/2026 | The Chatbot for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in version 2.3.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts… | |
| Modificada | Media (4.8) | 0.39% | — | Quantumcloud Conversational Forms FOR Chatbot | 6/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud Conversational Forms for ChatBot plugin <= 1.1.6 versions. | |
| Modificada | Alta (8.8) | 0.26% | — | Quantumcloud Chatbot | 23/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. | |
| Modificada | Crítica (9.3) | 1.3% | — | Kg-fashion-chatbot Project Kg-fashion-chatbot | 11/7/2022 | 17/6/2026 | The yuriyouzhou/KG-fashion-chatbot repository through 2018-05-22 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.2) | 1.0% | — | Chatbot APP With Suggestion Project Chatbot APP With Suggestion | 2/6/2022 | 17/6/2026 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/view_response&id=. | |
| Modificada | Alta (7.2) | 1.0% | — | Chatbot APP With Suggestion Project Chatbot APP With Suggestion | 2/6/2022 | 17/6/2026 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=responses/manage_response&id=. | |
| Modificada | Crítica (9.8) | 1.1% | — | Chatbot APP With Suggestion Project Chatbot APP With Suggestion | 2/6/2022 | 17/6/2026 | ChatBot App with Suggestion v1.0 is vulnerable to SQL Injection via /simple_chat_bot/admin/?page=user/manage_user&id=. | |
| Modificada | Media (6.5) | 0.98% | — | Chatbot APP With Suggestion Project Chatbot APP With Suggestion | 2/6/2022 | 17/6/2026 | ChatBot App with Suggestion v1.0 is vulnerable to Delete any file via /simple_chat_bot/classes/Master.php?f=delete_img. | |
| Modificada | Media (5.4) | 0.50% | — | Chatbot APP With Suggestion Project Chatbot APP With Suggestion | 24/5/2022 | 17/6/2026 | ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to Cross Site Scripting (XSS) via /simple_chat_bot/classes/Master.php?f=save_response. | |
| Modificada | Alta (8.8) | 0.97% | — | Chatbot APP With Suggestion Project Chatbot APP With Suggestion | 24/5/2022 | 17/6/2026 | ChatBot App with Suggestion in PHP/OOP v1.0 is vulnerable to SQL Injection via /simple_chat_bot/classes/Master.php?f=delete_response, id. | |
| Modificada | Crítica (9.8) | 1.8% | — | Chatbot Application With A Suggestion Feature Project Chatbot Application With A Suggestion Feature | 20/5/2022 | 17/6/2026 | ChatBot Application with a Suggestion Feature 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /simple_chat_bot/admin/responses/view_response.php. |