| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-65957 | Core Bot is Leaking Sensitive Credentials in Logs, Errors, and Messages | Intercore-Productions | Core-Bot | - | - | 2025-11-25 23:33:10 | Deep Dive |
| CVE-2025-13068 | Telegram Bot & Channel <= 4.1 - Unauthenticated Stored Cross-Site Scripting via Telegram Username | milmor | Telegram Bot & Channel | High | 7.2 | 2025-11-25 04:38:02 | Deep Dive |
| CVE-2025-12078 | ArtiBot Free Chat Bot for WebSites <= 1.1.7 - Reflected Cross-Site Scripting via PostMessage | artibot | ArtiBot Free Chat Bot for WebSites | Medium | 6.1 | 2025-11-18 08:27:38 | Deep Dive |
| CVE-2025-57935 | WordPress Bot Block – Stop Spam Referrals in Google Analytics Plugin <= 2.6 - Cross Site Scripting (XSS) Vulnerability | Ricky Dawn | Bot Block – Stop Spam Referrals in Google Analytics | Medium | 5.9 | 2025-09-22 18:25:03 | Deep Dive |
| CVE-2025-55244 | Azure Bot Service Elevation of Privilege Vulnerability | Microsoft | Azure Bot Service | Critical | 9.0 | 2025-09-04 23:09:50 | Deep Dive |
| CVE-2025-6722 | BitFire <= 4.5 - Unauthenticated Information Exposure | bitslip6 | BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security | Medium | 5.3 | 2025-08-02 09:23:31 | Deep Dive |
| CVE-2025-5018 | Hive Support <= 1.2.5 - Authenticated (Subscriber+) Missing Authorization via hs_update_ai_chat_settings and hive_lite_support_get_all_binbox | hivesupport | Hive Support | AI-Powered Help Desk, Live Chat and Chatbot | High | 7.1 | 2025-06-06 06:42:51 | Deep Dive |
| CVE-2025-5019 | Hive Support <= 1.2.5 - Cross-Site Request Forgery via hs_update_ai_chat_settings Function | hivesupport | Hive Support | AI-Powered Help Desk, Live Chat and Chatbot | Medium | 5.4 | 2025-06-06 06:42:49 | Deep Dive |
| CVE-2025-48268 | WordPress Bot for Telegram on WooCommerce plugin <= 1.2.6 - Broken Access Control Vulnerability | Guru Team | Bot for Telegram on WooCommerce | Medium | 4.3 | 2025-05-19 14:45:24 | Deep Dive |
| CVE-2025-47948 | Cocotais Bot has builtin .echo command injection | cocotais | cocotais-bot | High | 7.2 | 2025-05-17 18:42:24 | Deep Dive |
| CVE-2023-7197 | Marketing Twitter Bot <= 1.11 - Settings Update to Stored XSS via CSRF | Unknown | Marketing Twitter Bot | - | - | 2025-05-15 20:09:25 | Deep Dive |
| CVE-2025-30392 | Azure AI Bot Elevation of Privilege Vulnerability | Microsoft | Azure AI Bot Service | Critical | 9.8 | 2025-04-30 17:14:52 | Deep Dive |
| CVE-2025-30389 | Azure Bot Framework SDK Elevation of Privilege Vulnerability | Microsoft | Azure AI Bot Service | High | 8.7 | 2025-04-30 17:14:50 | Deep Dive |
| CVE-2025-21384 | Azure Health Bot Elevation of Privilege Vulnerability | Microsoft | Azure Health Bot | High | 8.3 | 2025-04-01 00:40:29 | Deep Dive |
| CVE-2025-28909 | WordPress WP No-Bot Question plugin <= 0.1.7 - Cross Site Request Forgery (CSRF) vulnerability | edwardw | WP No-Bot Question | Medium | 4.3 | 2025-03-11 21:00:57 | Deep Dive |
| CVE-2025-27106 | Code injection in binance-trading-bot | chrisleekr | binance-trading-bot | 高危 | - | 2025-02-21 21:18:18 | Deep Dive |
| CVE-2025-22542 | WordPress Virtual Bot Plugin <= 1.0.0 - SQL Injection vulnerability | Ofek Nakar | Virtual Bot | Critical | 9.3 | 2025-01-09 15:39:24 | Deep Dive |
| CVE-2025-22538 | WordPress Virtual Bot Plugin <= 1.0.0 - CSRF Cross Site Scripting (XSS) vulnerability | Ofek Nakar | Virtual Bot | High | 7.1 | 2025-01-07 14:57:24 | Deep Dive |
| CVE-2024-38789 | WordPress Telegram Bot & Channel plugin <= 3.8.2 - Cross Site Request Forgery (CSRF) vulnerability | Marco Milesi | Telegram Bot & Channel | Medium | 5.4 | 2025-01-02 12:01:09 | Deep Dive |
| CVE-2024-53992 | unzip-bot Allows Remote Code Execution (RCE) via archive extraction, password prompt, or video upload | EDM115 | unzip-bot | 超危 | - | 2024-12-02 17:03:23 | Deep Dive |