Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2760▲ 27 respecto a la semana anterior
Críticas / altas1467▲ 305 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.16%—Havelsan SEF AI Chatbot PlatformAI2/10/20262/10/2026
Improper certificate validation vulnerability in HAVELSAN Inc. Sef - AI Chatbot Platform allows Adversary in the Middle (AiTM). This issue affects Sef - AI Chatbot Platform: before 2.1. NOTE: The vendor was contacted and it was learned that the product is not supported.
AplazadaAlta (8.8)0.48%—Quantumcloud Conversational Forms FOR ChatbotAI30/9/202630/9/2026
Subscriber PHP Object Injection in Conversational Forms for ChatBot <= 1.5.0 versions.
AplazadaAlta (7.1)0.44%—Chatbot UIAISupabaseAI4/9/202624/9/2026
Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by supplying arbitrary file UUIDs. The endpoint uses a service-role Supabase client that bypasses row-level security and fails to validate file…
AplazadaAlta (7.5)0.42%—Siteleads Lead Generation Contact Widget AND AI ChatbotAI24/8/202626/8/2026
Unauthenticated Sensitive Data Exposure in Lead Generation Contact Widget &amp; AI Chatbot: Chat Button, Phone Call, Telegram, Email – SiteLeads <= 1.2.0 versions.
AplazadaMedia (6.1)0.28%—Nopaperforms Niaa-chatbotAI24/8/20269/9/2026
A cross-site scripting (XSS) vulnerability in Support chatbot in Nopaperforms Niaa-Chatbot through 2022-05-17 allows remote attackers to inject arbitrary web script or HTML via the Enter email parameter.
AplazadaAlta (7.5)2.0%—Aiwu AI Chatbot Workflow AutomationAI5/8/202612/8/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6. This is due to the `getCurrentTaskResults()` method in `modules/workspace/controller.php` being accessible without authentication or authorization checks. The…
AplazadaAlta (7.5)0.41%—AI Chatbot FOR WoocommerceAI2/8/202626/8/2026
The AI ChatBot for WooCommerce WordPress plugin before 4.8.4 does not perform any authorization or nonce check on one of its AJAX actions, allowing unauthenticated users to abuse the site owner's stored third-party API key to send requests billed to the owner's account and, when an optional feature is enabled, to…
AplazadaMedia (5.3)0.40%—ChatbotAI28/7/202628/7/2026
The Chatbot plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.5.9 via the wpcs_send_email() AJAX handler. This is due to the wpcs_send_email() function being registered on both wp_ajax_wpcs_send_email and wp_ajax_nopriv_wpcs_send_email with no nonce verification,…
AplazadaMedia (5.3)0.47%—Wpbot AI Chatbot FOR Live Support Lead Generation AI ServicesAI28/7/202628/7/2026
The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 8.5.9 via the wpbot_send_email_transcript_free. This makes it possible for unauthenticated attackers to exfiltrate full chat transcripts and…
AplazadaMedia (6.5)0.22%—Quantumcloud Chatbot FOR Ecommerce WoowbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.
AplazadaAlta (7.1)0.25%—Quantumcloud ChatbotAI13/7/202613/7/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot chatbot allows Stored XSS.This issue affects ChatBot: from n/a through <= 8.3.7.
AplazadaMedia (5.3)0.56%—Aiwu AI Chatbot Workflow AutomationAI11/7/202614/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft…
AplazadaMedia (5.3)0.52%—Aiwu AI Chatbot Workflow AutomationAI11/7/202615/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's…
AplazadaAlta (7.1)0.25%—ChatbotAI2/7/20262/7/2026
Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
AplazadaAlta (7.5)0.43%—Openai Chatbot FOR Wordpress HelperAI2/7/202630/9/2026
Unauthenticated Arbitrary Content Deletion in OpenAI Chatbot for WordPress – Helper <= 1.1.4 versions.
AplazadaAlta (7.5)0.43%—Quantumcloud Conversational Forms FOR ChatbotAI17/6/20261/10/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue affects Conversational Forms for ChatBot: from n/a through 1.1.8.
AplazadaAlta (7.4)0.28%—Chatway Live Chat - AI Chatbot Customer Support FAQ & Helpdesk Customer Service & Chat ButtonsAI15/6/202617/6/2026
Subscriber Sensitive Data Exposure in Chatway Live Chat &#8211; AI Chatbot, Customer Support, FAQ &amp; Helpdesk Customer Service &amp; Chat Buttons <= 1.4.8 versions.
AplazadaAlta (7.1)0.32%—ChatbotAI15/6/202617/6/2026
Subscriber Broken Access Control in ChatBot <= 7.9.7 versions.
AplazadaMedia (6.4)0.28%—Aiwu AI Chatbot Workflow AutomationAI20/5/202624/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'X-Forwarded-For' header in versions up to, and including, 1.4.14 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…
AplazadaAlta (7.5)0.69%—Aiwu AI Chatbot Workflow AutomationAI12/5/202617/6/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4.17 due to insufficient escaping on user supplied parameters and lack of sufficient preparation on the existing SQL query in the getListForTbl() function. This makes it possible for…
AnalizadaAlta (7)0.33%—1millionbot Millie Chatbot31/3/202617/6/2026
Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation ID. The vulnerability is present in the endpoint 'api.1millionbot.com/api/public/conversations/' and, if exploited, could allow a remote…
AnalizadaAlta (8.7)0.45%—1millionbot Millie Chatbot31/3/202617/6/2026
Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that, upon receiving an affirmative response ('true'), the model executes the injected instruction), causing it to…
AplazadaMedia (6.9)0.44%—Hijiffy ChatbotAI26/3/202617/6/2026
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'visitor' in '/api/v1/webchat/message'.
AplazadaMedia (6.9)0.41%—Hijiffy ChatbotAI26/3/202617/6/2026
Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' in '/api/v1/download/<ID>/'.
AplazadaCrítica (9.3)0.40%—Quantumcloud ChatbotAI25/3/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.