Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
1143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.35% | 💥 PoC | LET S ChatAI | 28/7/2026 | 30/7/2026 | Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to download file attachments from private and password-protected rooms they are not a member of by exploiting missing room membership checks in the file retrieval route. Attackers can enumerate adjacent… | |
| Aplazada | Alta (7.1) | 0.44% | 💥 PoC | Lets ChatAI | 28/7/2026 | 30/7/2026 | Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid 24-character hex string room parameter that matches no document in the database. Attackers can send a crafted GET /messages request causing an uncaught TypeError in an… | |
| Aplazada | Media (5.3) | 0.40% | — | ChatbotAI | 28/7/2026 | 28/7/2026 | The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification,… | |
| Aplazada | Media (5.3) | 0.47% | — | Wpbot AI Chatbot FOR Live Support Lead Generation AI ServicesAI | 28/7/2026 | 28/7/2026 | The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and… | |
| Aplazada | Media (6.5) | 0.41% | — | Premio Chaty PROAI | 28/7/2026 | 28/7/2026 | The Chaty Pro plugin for WordPress is vulnerable to Authenticated Time-Based Blind SQL Injection in versions up to and including 3.5.5. This is due to the fetch_custom_field() function in admin/class-admin-base.php retrieving the widget_id POST parameter via filter_input(INPUT_POST, ...) and directly concatenating the… | |
| Aplazada | Crítica (9.1) | 0.45% | — | Wechat Qrcode LoginAI | 27/7/2026 | 27/7/2026 | The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem… | |
| Aplazada | Alta (8.8) | 0.70% | — | ChatwootAI | 23/7/2026 | 17/9/2026 | Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to create arbitrary ActiveStorage blobs in any tenant account. Attackers can exploit missing authentication checks to resolve any account and conversation, then obtain signed… | |
| Aplazada | Alta (7.1) | 0.40% | — | Chat2dbAI | 17/7/2026 | 23/7/2026 | Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler calls dataSourceService.queryExistent(id, ...) without an ownership check and returns the decrypted password field, allowing any authenticated non-admin user to enumerate… | |
| Aplazada | Media (6.4) | 0.35% | — | ChathelpAI | 17/7/2026 | 17/7/2026 | The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes in all versions up to, and including, 3.5.1 due to insufficient input sanitization and output escaping. This makes it… | |
| Aplazada | Alta (7.7) | 0.51% | — | StoatchatAI | 16/7/2026 | 16/7/2026 | stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypass the DNS-based IP blocklist by exploiting incomplete address validation in the url_is_blacklisted function, which inspects only the first resolved address while the… | |
| Aplazada | Alta (8.6) | 0.96% | — | SimplechatAI | 16/7/2026 | 16/7/2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several plugin validation routes in application/single_app/plugin_validation_endpoint.py, including `POST /api/admin/plugins/test-instantiation`, `GET… | |
| Aplazada | Media (4.3) | 0.91% | — | SimplechatAI | 16/7/2026 | 16/7/2026 | SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.203, the authenticated GET /api/user/info/<user_id> and GET /api/user/profile-image/<user_id> endpoints in application/single_app/route_backend_users.py accepted a caller-supplied… | |
| Aplazada | Crítica (9.2) | 0.41% | — | StoatchatAI | 16/7/2026 | 16/7/2026 | stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrary URLs without DNS resolution filtering or private IP range validation. Attackers can enumerate internal services, fingerprint applications, and reach instance metadata… | |
| Aplazada | Media (6.9) | 0.45% | — | StoatchatAI | 16/7/2026 | 18/7/2026 | stoatchat versions before 0.7.8 fail to enforce account creation restrictions including invite-only mode, email verification, captcha, and shield verification. Attackers can create unlimited accounts with unverified email addresses, increasing denial-of-service risk and compromising service integrity. | |
| Aplazada | Alta (7.6) | 0.48% | — | StoatchatAI | 16/7/2026 | 6/10/2026 | stoatchat (delta/Revolt) versions from 20241213-1 before 20250210-1 allow users with only ViewChannel (read) permission on a channel to fetch that channel's webhooks, including their tokens, because the webhook fetch endpoint checked for ViewChannel instead of ManageWebhooks. Using a retrieved token, an attacker can… | |
| Aplazada | Alta (8.7) | 0.67% | — | StoatchatAI | 16/7/2026 | 6/10/2026 | stoatchat (delta) versions before 20250210-1 (0.8.2) contain a logic error in the query messages route. When fetching messages 'nearby' another message, the database query can be given a message limit of zero, which the database interprets as 'no limit'. A remote unauthenticated attacker can craft nearby message fetch… | |
| Aplazada | Media (4.4) | 0.33% | — | MxchatAI | 16/7/2026 | 16/7/2026 | The MxChat – AI Chatbot & Content Generation for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Aplazada | Baja (2.1) | 0.37% | — | Zhayujie Chatgpt-on-wechatAI | 14/7/2026 | 14/7/2026 | A security flaw has been discovered in zhayujie chatgpt-on-wechat CowAgent up to 2.1.1. This issue affects the function Vision._download_to_data_url of the file agent/tools/vision/vision.py of the component Vision Tool. Performing a manipulation of the argument image results in server-side request forgery. It is… | |
| Aplazada | Media (6.5) | 0.22% | — | Quantumcloud Chatbot FOR Ecommerce WoowbotAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce – WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce – WoowBot: from n/a through <= 4.6.1. | |
| Aplazada | Alta (7.1) | 0.25% | — | Wppool FormychatAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPPOOL FormyChat social-contact-form allows Stored XSS.This issue affects FormyChat: from n/a through <= 2.15.3. | |
| Aplazada | Alta (7.1) | 0.25% | — | Quantumcloud ChatbotAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7. | |
| Aplazada | Media (5.3) | 0.56% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 14/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft… | |
| Aplazada | Media (5.3) | 0.52% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 15/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's… | |
| Aplazada | Alta (7.5) | 0.66% | — | Chat HelpAI | 10/7/2026 | 10/7/2026 | The Chat Help – Click to Chat Button & Form plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.1.3 via the REST API endpoints /wp-json/chat-help/v1/leads and /wp-json/chat-help/v1/leads/{id}. This is due to the plugin not performing any authentication and… | |
| Aplazada | Media (5.5) | 0.12% | — | ChatterbotAI | 9/7/2026 | 9/7/2026 | ChatterBot is a machine learning, conversational dialog engine for creating chat bots. Prior to 1.2.14, UbuntuCorpusTrainer.extract() uses a predictable home-rooted output directory (~/ubuntu_data/ubuntu_dialogs) with a check-then-create pattern followed by tar.extractall(path=self.data_path), allowing a local… |