Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

45 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.38%—Livehelperchat Live Helper ChatAI14/5/202617/6/2026
Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash…
AnalizadaMedia (4.9)0.34%—Livehelperchat Live Helper Chat26/2/202617/6/2026
Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats…
AplazadaMedia (6.9)0.28%—Livehelperchat Live Helper ChatAI28/1/202617/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the…
AnalizadaMedia (6.5)1.5%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
AnalizadaMedia (5.4)0.92%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
AnalizadaMedia (5.4)0.95%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
AnalizadaMedia (5.4)0.97%—Livehelperchat Live Helper Chat21/7/202517/6/2026
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.
AplazadaBaja (2)0.28%—Livehelperchat LHC PHP ResqueAI11/7/202517/6/2026
A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /site_admin/lhcphpresque/list/ of the component List Handler. The manipulation of the argument queue name leads to cross…
AnalizadaCrítica (9.8)1.5%—Livehelperchat Live Helper Chat29/2/202417/6/2026
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
ModificadaMedia (6.1)0.65%—Livehelperchat Live Helper Chat29/4/202217/6/2026
Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application.
ModificadaAlta (8.8)1.3%—Livehelperchat Live Helper Chat7/4/202217/6/2026
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
ModificadaMedia (6.1)0.73%—Livehelperchat Live Helper Chat6/4/202217/6/2026
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
ModificadaAlta (8.2)0.56%—Livehelperchat Live Helper Chat5/4/202217/6/2026
Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.1)0.58%—Livehelperchat Live Helper Chat5/4/202217/6/2026
SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191
ModificadaAlta (7.5)1.3%—Livehelperchat Live Helper Chat31/3/202217/6/2026
Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaAlta (8.1)0.95%—Livehelperchat Live Helper Chat31/3/202217/6/2026
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
ModificadaMedia (5.4)0.61%—Livehelperchat Live Helper Chat16/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.61%—Livehelperchat Live Helper Chat6/2/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.64%—Livehelperchat Live Helper Chat28/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.55%—Livehelperchat Live Helper Chat28/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.63%—Livehelperchat27/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (5.4)0.77%—Livehelperchat27/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
ModificadaMedia (4.8)0.70%—Livehelperchat Live Helper Chat26/1/202217/6/2026
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.