| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-11762 | HubSpot All-In-One Marketing - Forms, Popups, Live Chat <= 11.3.32 - Missing Authorization to Authenticated (Contributor+) Installed Plugin Disclosure | hubspotdev | HubSpot All-In-One Marketing – Forms, Popups, Live Chat | Medium | 4.3 | 2026-04-24 07:45:07 | Deep Dive |
| CVE-2026-29197 | XX软件<8.4.0等版权限检查拼写漏洞致越权读日志 | Rocket.Chat | Rocket.Chat | - | - | 2026-04-23 23:19:41 | Deep Dive |
| CVE-2026-29198 | Rocket.Chat SQL注入漏洞 | Rocket.Chat | Rocket.Chat | - | - | 2026-04-22 23:30:15 | Deep Dive |
| CVE-2026-6588 | serge-chat serge Model API Endpoint model.py delete_model missing authentication | serge-chat | serge | Medium | 6.5 | 2026-04-20 00:15:12 | Deep Dive |
| CVE-2026-23653 | GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability | Microsoft | Microsoft Visual Studio Code CoPilot Chat Extension | Medium | 5.7 | 2026-04-14 16:56:53 | Deep Dive |
| CVE-2026-22560 | Rocket.Chat 安全漏洞 | Rocket.Chat | Rocket.Chat | 中危 | - | 2026-04-10 17:00:12 | Deep Dive |
| CVE-2026-39696 | WordPress Elfsight WhatsApp Chat CC plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability | Elfsight | Elfsight WhatsApp Chat CC | - | - | 2026-04-08 08:30:46 | Deep Dive |
| CVE-2026-22665 | prompts.chat Identity Confusion via Case-Sensitive Username Handling | f | prompts.chat | High | 8.1 | 2026-04-03 20:28:10 | Deep Dive |
| CVE-2026-22664 | prompts.chat SSRF via Fal.ai Media Status Polling | f | prompts.chat | High | 7.7 | 2026-04-03 20:27:48 | Deep Dive |
| CVE-2026-22663 | prompts.chat Authorization Bypass Information Disclosure | f | prompts.chat | High | 7.5 | 2026-04-03 20:27:25 | Deep Dive |
| CVE-2026-22662 | prompts.chat Blind SSRF via media-generate | f | prompts.chat | Medium | 4.3 | 2026-04-03 20:27:03 | Deep Dive |
| CVE-2026-22661 | prompts.chat Path Traversal via Skill File Handling | f | prompts.chat | High | 8.1 | 2026-04-03 20:26:29 | Deep Dive |
| CVE-2026-4400 | Multiple vulnerabilities in 1millionbot Millie chatbot | 1millionbot | Millie chat | 中危 | - | 2026-03-31 10:12:08 | Deep Dive |
| CVE-2026-4399 | Multiple vulnerabilities in 1millionbot Millie chatbot | 1millionbot | Millie chat | 中危 | - | 2026-03-31 10:10:09 | Deep Dive |
| CVE-2026-3321 | Authorization Bypass in ON24 Q&A chat | ON24 | ON24 Q&A chat | 中危 | - | 2026-03-30 13:17:51 | Deep Dive |
| CVE-2026-25377 | WordPress Addon Jobsearch Chat plugin <= 3.0 - SQL Injection vulnerability | eyecix | Addon Jobsearch Chat | Critical | 9.3 | 2026-03-25 16:14:47 | Deep Dive |
| CVE-2026-25376 | WordPress Addon Jobsearch Chat plugin <= 3.0 - Reflected Cross Site Scripting (XSS) vulnerability | eyecix | Addon Jobsearch Chat | High | 7.1 | 2026-03-25 16:14:46 | Deep Dive |
| CVE-2019-25613 | Easy Chat Server 3.1 Denial of Service via message Parameter | Echatserver | Easy Chat | High | 7.5 | 2026-03-22 13:38:46 | Deep Dive |
| CVE-2026-1253 | Group Chat & Video Chat by AtomChat <= 1.1.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Options Update | atomchat | Group Chat & Video Chat by AtomChat | Medium | 4.3 | 2026-03-21 03:26:48 | Deep Dive |
| CVE-2026-2987 | Simple Ajax Chat <= 20260217 - Unauthenticated Stored Cross-Site Scripting via 'c' | specialk | Simple Ajax Chat – Add a Fast, Secure Chat Box | Medium | 6.1 | 2026-03-12 12:26:32 | Deep Dive |