Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 86 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.30% | — | Notchatbot Webchat WidgetAI | 18/3/2026 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the NotChatbot WebChat widget thru 1.4.4. User-supplied input is not properly sanitized before being stored and rendered in the chat conversation history. This allows an attacker to inject arbitrary JavaScript code which is executed when the chat history is… | |
| Aplazada | Alta (8.8) | 0.47% | — | Xelion WebchatAI | 24/4/2025 | 17/6/2026 | The Xelion Webchat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the xwc_save_settings() function in all versions up to, and including, 9.1.0. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Aplazada | Alta (8.8) | 0.40% | — | Jauhari Xelion Xelion WebchatAI | 17/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in Jauhari Xelion Xelion Webchat xelion-webchat allows Privilege Escalation.This issue affects Xelion Webchat: from n/a through <= 9.1.0. | |
| Modificada | Alta (8.8) | 0.82% | — | Onwebchat Live Chat - Live Support | 15/10/2020 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.1% | — | Daniel Toma Webchat | 3/7/2007 | 16/6/2026 | SQL injection vulnerability in login.php in WebChat 0.78 allows remote attackers to execute arbitrary SQL commands via the rid parameter. | |
| Modificada | Alta (7.5) | 8.3% | — | Webchat.org Webchat | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP code via a URL in the WEBCHATPATH parameter. | |
| Modificada | Alta (7.5) | 1.1% | — | Webchat.org WebchatXoops | 31/12/2002 | 16/6/2026 | SQL injection vulnerability in index.php of WebChat 1.5 included in XOOPS 1.0 allows remote attackers to execute arbitrary SQL commands via the roomid parameter. |