Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
45 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.38% | — | Livehelperchat Live Helper ChatAI | 14/5/2026 | 17/6/2026 | Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can change the chat hash… | |
| Analizada | Media (4.9) | 0.34% | — | Livehelperchat Live Helper Chat | 26/2/2026 | 17/6/2026 | Live Helper Chat is an open-source application that enables live support websites. In versions up to and including 4.52, three chat action endpoints (holdaction.php, blockuser.php, and transferchat.php) load chat objects by ID without calling `erLhcoreClassChat::hasAccessToRead()`, allowing operators to act on chats… | |
| Aplazada | Media (6.9) | 0.28% | — | Livehelperchat Live Helper ChatAI | 28/1/2026 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in the PDF file upload functionality of Live Helper Chat, versions prior to 4.72. An attacker can upload a malicious PDF file containing an XSS payload, which will be executed in the user's context when they download and open the file via the link generated by the… | |
| Analizada | Media (6.5) | 1.5% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter. | |
| Analizada | Media (5.4) | 0.92% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter. | |
| Analizada | Media (5.4) | 0.92% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | |
| Analizada | Media (5.4) | 0.92% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | |
| Analizada | Media (5.4) | 0.95% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists. | |
| Analizada | Media (5.4) | 0.97% | — | Livehelperchat Live Helper Chat | 21/7/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter. | |
| Aplazada | Baja (2) | 0.28% | — | Livehelperchat LHC PHP ResqueAI | 11/7/2025 | 17/6/2026 | A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /site_admin/lhcphpresque/list/ of the component List Handler. The manipulation of the argument queue name leads to cross… | |
| Analizada | Crítica (9.8) | 1.5% | — | Livehelperchat Live Helper Chat | 29/2/2024 | 17/6/2026 | Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php. | |
| Modificada | Media (6.1) | 0.65% | — | Livehelperchat Live Helper Chat | 29/4/2022 | 17/6/2026 | Cross-site Scripting (XSS) in GitHub repository livehelperchat/livehelperchat prior to 3.99v. The attacker can execute malicious JavaScript on the application. | |
| Modificada | Alta (8.8) | 1.3% | — | Livehelperchat Live Helper Chat | 7/4/2022 | 17/6/2026 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. | |
| Modificada | Media (6.1) | 0.73% | — | Livehelperchat Live Helper Chat | 6/4/2022 | 17/6/2026 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device. | |
| Modificada | Alta (8.2) | 0.56% | — | Livehelperchat Live Helper Chat | 5/4/2022 | 17/6/2026 | Weak secrethash can be brute-forced in GitHub repository livehelperchat/livehelperchat prior to 3.96. | |
| Modificada | Alta (8.1) | 0.58% | — | Livehelperchat Live Helper Chat | 5/4/2022 | 17/6/2026 | SSRF filter bypass port 80, 433 in GitHub repository livehelperchat/livehelperchat prior to 3.67v. An attacker could make the application perform arbitrary requests, bypass CVE-2022-1191 | |
| Modificada | Alta (7.5) | 1.3% | — | Livehelperchat Live Helper Chat | 31/3/2022 | 17/6/2026 | Loose comparison causes IDOR on multiple endpoints in GitHub repository livehelperchat/livehelperchat prior to 3.96. | |
| Modificada | Alta (8.1) | 0.95% | — | Livehelperchat Live Helper Chat | 31/3/2022 | 17/6/2026 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. | |
| Modificada | Media (5.4) | 0.61% | — | Livehelperchat Live Helper Chat | 16/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.61% | — | Livehelperchat Live Helper Chat | 6/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.64% | — | Livehelperchat Live Helper Chat | 28/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.55% | — | Livehelperchat Live Helper Chat | 28/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.63% | — | Livehelperchat | 27/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (5.4) | 0.77% | — | Livehelperchat | 27/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | |
| Modificada | Media (4.8) | 0.70% | — | Livehelperchat Live Helper Chat | 26/1/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. |