Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.41% | — | Code-projects Simple ChatboxAI | 13/4/2026 | 17/6/2026 | A vulnerability was determined in code-projects Simple ChatBox up to 1.0. This affects an unknown part of the file /chatbox/insert.php of the component Endpoint. Executing a manipulation of the argument msg can lead to sql injection. It is possible to launch the attack remotely. The exploit has been publicly disclosed… | |
| Aplazada | Media (5.5) | 0.51% | — | Code-projects Simple ChatboxAI | 13/4/2026 | 17/6/2026 | A vulnerability was found in code-projects Simple ChatBox 1.0. Affected by this issue is the function SimpleChatbox_PHP of the file chatbox.sql of the component Endpoint. Performing a manipulation results in file and directory information exposure. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Baja (2.1) | 0.45% | — | Code-projects Simple ChatboxAI | 13/4/2026 | 17/6/2026 | A vulnerability has been found in code-projects Simple ChatBox up to 1.0. Affected by this vulnerability is an unknown functionality of the file /chatbox/insert.php of the component Endpoint. Such manipulation of the argument msg leads to cross site scripting. The attack may be performed from remote. The exploit has… | |
| Aplazada | Media (5.5) | 2.1% | — | Getgist ChatboxAI | 12/4/2026 | 17/6/2026 | A flaw has been found in chatboxai chatbox up to 1.20.0. This impacts the function StdioClientTransport of the file src/main/mcp/ipc-stdio-transport.ts of the component Model Context Protocol Server Management System. Executing a manipulation of the argument args/env can lead to os command injection. The attack can be… | |
| Aplazada | Alta (8.1) | 0.29% | — | Tawk.to Chatbox WidgetAI | 29/9/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in tawk.to chatbox widget v4 allows attackers to execute arbitrary Javascript in the context of the user's browser via injecting a crafted payload into the vulnerable parameter. | |
| Aplazada | Baja (2.1) | 0.25% | — | Getgist ChatboxAI | 29/8/2025 | 17/6/2026 | A vulnerability was found in shafhasan chatbox up to 156a39cde62f78532c3265a70eda12c70907e56f. This impacts an unknown function of the file /chat.php. The manipulation of the argument user_id results in sql injection. The attack may be performed from a remote location. The exploit has been made public and could be… | |
| Aplazada | Media (6.5) | 0.17% | — | Alexvtn Wa-chatbox-managerAI | 27/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Stored XSS.This issue affects Chatbox Manager: from n/a through <= 1.2.6. | |
| Aplazada | Media (5.4) | 0.22% | — | Alexvtn Wa-chatbox-managerAI | 16/7/2025 | 17/6/2026 | Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Chatbox Manager: from n/a through <= 1.2.5. | |
| Aplazada | Media (5.3) | 0.46% | — | Alexvtn Wa-chatbox-managerAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Chatbox Manager: from n/a through <= 1.2.2. | |
| Analizada | Baja (3.8) | 0.29% | — | Angeljudesuarez Simple Chatbox | 21/2/2025 | 17/6/2026 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /del.php. The attack can use SQL injection to obtain sensitive data. | |
| Analizada | Baja (3.8) | 0.29% | — | Angeljudesuarez Simple Chatbox | 21/2/2025 | 17/6/2026 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /admin.php. The attack can use SQL injection to obtain sensitive data. | |
| Analizada | Alta (7.2) | 0.47% | — | Angeljudesuarez Simple Chatbox | 21/2/2025 | 17/6/2026 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data. | |
| Analizada | Media (6.4) | 0.38% | — | Angeljudesuarez Simple Chatbox | 21/2/2025 | 17/6/2026 | A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data. | |
| Modificada | Media (6.1) | 1.1% | — | Getgist Chatbox | 23/2/2021 | 17/6/2026 | Chatbox is affected by cross-site scripting (XSS). An attacker has to upload any XSS payload with SVG, XML file in Chatbox. There is no restriction on file upload in Chatbox which leads to stored XSS. | |
| Modificada | Media (6.1) | 0.71% | — | Urlchatbox Chat Anywhere | 27/12/2018 | 17/6/2026 | The Chat Anywhere extension 2.4.0 for Chrome allows XSS via crafted use of <<a> in a message, because a danmuWrapper DIV element in chatbox-only\danmu.js is outside the scope of a Content Security Policy (CSP). | |
| Modificada | Media (5.4) | 0.27% | — | Chatbox - Chat Rooms | 19/9/2014 | 17/6/2026 | The ChatBox - Chat Rooms (aka com.droidchatroom.messengerapp) application 2.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 3.3% | — | E107 Chatbox PluginE107 | 23/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Chatbox Plugin 1.0 in e107 0.7.2 allows remote attackers to inject arbitrary HTML or web script via a Chatbox, as demonstrated using a SCRIPT element. |