Vulnerabilities

Summary — last 7 days

New vulnerabilities2,722▼ 6 vs. last week
Critical / high1,451▲ 315 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
–

8 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (6.5)0.52%—LivechatAI7/12/20246/17/2026
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
DeferredCritical (10)0.61%—Livechatpro Module Live Chat PROAI6/19/20246/17/2026
In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file.
ModifiedHigh (8.8)0.27%—Livechat12/18/20236/17/2026
Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.
ModifiedMedium (6.1)0.77%—Rocket.chat Livechat4/1/20226/17/2026
A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance.
ModifiedHigh (7.5)1.0%—Joompolitan COM Livechat7/30/20096/16/2026
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModifiedHigh (7.5)2.3%—Joompolitan COM Livechat7/30/20096/16/2026
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string.
ModifiedHigh (7.5)1.0%—Joompolitan COM Livechat7/30/20096/16/2026
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php.
ModifiedMedium (4.3)1.7%—Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A12/31/20046/16/2026
Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa.