Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.38%—Livehelperchat Live Helper ChatAI14/5/202617/6/2026
Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash…
AnalizadaMedia (4.9)0.34%—Livehelperchat Live Helper Chat26/2/202617/6/2026
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats…
AplazadaMedia (6.9)0.28%—Livehelperchat Live Helper ChatAI28/1/202617/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the…
AnalizadaMedia (6.5)1.5%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
AnalizadaMedia (5.4)0.95%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
AnalizadaMedia (5.4)0.97%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.
AnalizadaCrítica (9.8)1.5%—Livehelperchat Live Helper Chat29/2/202417/6/2026
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
ModificadaMedia (6.1)0.65%—Livehelperchat Live Helper Chat29/4/202217/6/2026
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
ModificadaAlta (8.8)1.3%—Livehelperchat Live Helper Chat7/4/202217/6/2026
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
ModificadaMedia (6.1)0.73%—Livehelperchat Live Helper Chat6/4/202217/6/2026
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
ModificadaAlta (8.2)0.56%—Livehelperchat Live Helper Chat5/4/202217/6/2026
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.1)0.58%—Livehelperchat Live Helper Chat5/4/202217/6/2026
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
ModificadaAlta (7.5)1.3%—Livehelperchat Live Helper Chat31/3/202217/6/2026
Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.1)0.95%—Livehelperchat Live Helper Chat31/3/202217/6/2026
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaMedia (5.4)0.61%—Livehelperchat Live Helper Chat16/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.61%—Livehelperchat Live Helper Chat6/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.64%—Livehelperchat Live Helper Chat28/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.55%—Livehelperchat Live Helper Chat28/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (4.8)0.70%—Livehelperchat Live Helper Chat26/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.69%—Livehelperchat Live Helper Chat26/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (6.6)1.1%—Livehelperchat Live Helper Chat19/1/202217/6/2026
Authorization Bypass Through User-Controlled Key in Packagist remdex/livehelperchat prior to 3.92v.
ModificadaMedia (4.3)0.43%—Livehelperchat Live Helper Chat14/1/202217/6/2026
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)