Vulnerabilities
Summary — last 7 days
New vulnerabilities2,774▼ 324 vs. last week
Critical / high1,284▼ 239 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)214▼ 107 vs. last week
5 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Medium (6.1) | 0.28% | — | TwchatAI | 12/7/2024 | 6/17/2026 | The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.0.4. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Modified | Critical (9.8) | 19% | 💥 Exploit | Wchat Project Wchat | 1/24/2018 | 6/17/2026 | SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field. | |
| Modified | High (7.5) | 1.3% | — | Mwchat PRO | 11/15/2006 | 6/16/2026 | Multiple PHP remote file inclusion vulnerabilities in MWChat Pro 7.0 allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[MWCHAT_Libs] parameter to (1) about.php, (2) buddy.php, (3) chat.php, (4) dialog.php, (5) head.php, (6) help.php, (7) index.php, and (8) license.php, different vectors than… | |
| Modified | High (7.5) | 2.0% | 💥 Exploit | Appindex Mwchat | 10/27/2005 | 6/16/2026 | SQL injection vulnerability in chat.php in MWChat 6.8 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modified | High (7.5) | 1.9% | — | Appindex Mwchat | 6/7/2005 | 6/16/2026 | PHP remote file inclusion vulnerability in start_lobby.php in MWChat 6.x allows remote attackers to execute arbitrary PHP code via the CONFIG[MWCHAT_Libs] parameter. |