Vulnerabilities
Summary — last 7 days
New vulnerabilities2,722▼ 6 vs. last week
Critical / high1,451▲ 315 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)85▼ 441 vs. last week
8 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.5) | 0.52% | — | LivechatAI | 7/12/2024 | 6/17/2026 | Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory. | |
| Deferred | Critical (10) | 0.61% | — | Livechatpro Module Live Chat PROAI | 6/19/2024 | 6/17/2026 | In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file. | |
| Modified | High (8.8) | 0.27% | — | Livechat | 12/18/2023 | 6/17/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15. | |
| Modified | Medium (6.1) | 0.77% | — | Rocket.chat Livechat | 4/1/2022 | 6/17/2026 | A blind self XSS vulnerability exists in RocketChat LiveChat <v1.9 that could allow an attacker to trick a victim pasting malicious code in their chat instance. | |
| Modified | High (7.5) | 1.0% | — | Joompolitan COM Livechat | 7/30/2009 | 6/16/2026 | SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the last parameter to getChatRoom.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modified | High (7.5) | 2.3% | — | Joompolitan COM Livechat | 7/30/2009 | 6/16/2026 | Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP proxy to hide network scanning activities or scan internal networks via a GET request with a full URL in the query string. | |
| Modified | High (7.5) | 1.0% | — | Joompolitan COM Livechat | 7/30/2009 | 6/16/2026 | Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the last parameter to (1) getChat.php, (2) getChatRoom.php, and (3) getSavedChatRooms.php. | |
| Modified | Medium (4.3) | 1.7% | — | Liveworld LivechatLiveworld LivefocusgroupLiveworld LiveforumLiveworld Liveq AND A | 12/31/2004 | 6/16/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LiveWorld products, possibly including (1) LiveForum, (2) LiveQ&A, (3) LiveChat, and (4) LiveFocusGroup, allow remote attackers to inject arbitrary web script or HTML via the q parameter in (a) search.jsp, (b) findclub!execute.jspa, and (c) search!execute.jspa. |