| CVE-2026-23807 | WordPress WP Telegram Widget and Join Link plugin <= 2.2.13 - Reflected Cross Site Scripting (XSS) vulnerability | WP Socio | WP Telegram Widget and Join Link | High | 7.1 | 2026-03-25 16:14:30 | Deep Dive |
| CVE-2021-47793 | Telegram Desktop 2.9.2 - Denial of Service (PoC) | Telegram | Telegram Desktop | High | 7.5 | 2026-01-15 23:25:43 | Deep Dive |
| CVE-2025-68589 | WordPress WP Telegram Widget and Join Link plugin <= 2.2.12 - Broken Access Control vulnerability | WP Socio | WP Telegram Widget and Join Link | Medium | 5.3 | 2025-12-24 13:10:43 | Deep Dive |
| CVE-2025-62993 | WordPress Notification for Telegram plugin <= 3.5.1 - Broken Access Control vulnerability | rainafarai | Notification for Telegram | Medium | 4.3 | 2025-12-09 14:52:25 | Deep Dive |
| CVE-2025-13068 | Telegram Bot & Channel <= 4.1 - Unauthenticated Stored Cross-Site Scripting via Telegram Username | milmor | Telegram Bot & Channel | High | 7.2 | 2025-11-25 04:38:02 | Deep Dive |
| CVE-2025-58794 | WordPress Notification for Telegram plugin <= 3.5.1 - Cross Site Request Forgery (CSRF) vulnerability | rainafarai | Notification for Telegram | Medium | 4.3 | 2025-09-05 13:45:04 | Deep Dive |
| CVE-2025-30949 | WordPress Site Chat on Telegram plugin <= 1.0.4 - PHP Object Injection Vulnerability | Guru Team | Site Chat on Telegram | Critical | 9.8 | 2025-07-16 11:28:09 | Deep Dive |
| CVE-2025-5939 | Telegram for WP <= 1.6.1 - Authenticated (Admin+) Stored Cross-Site Scripting | amir-mousavi | Telegram for WP | Medium | 4.4 | 2025-06-13 01:47:50 | Deep Dive |
| CVE-2025-5236 | NinjaTeam Chat for Telegram <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via username Parameter | ninjateam | WP Telegram Chat Widget | Medium | 6.4 | 2025-05-30 07:23:41 | Deep Dive |
| CVE-2025-48268 | WordPress Bot for Telegram on WooCommerce plugin <= 1.2.6 - Broken Access Control Vulnerability | Guru Team | Bot for Telegram on WooCommerce | Medium | 4.3 | 2025-05-19 14:45:24 | Deep Dive |
| CVE-2025-1450 | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | premio | Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty | Medium | 6.4 | 2025-02-27 09:21:49 | Deep Dive |
| CVE-2024-38789 | WordPress Telegram Bot & Channel plugin <= 3.8.2 - Cross Site Request Forgery (CSRF) vulnerability | Marco Milesi | Telegram Bot & Channel | Medium | 5.4 | 2025-01-02 12:01:09 | Deep Dive |
| CVE-2024-11885 | NinjaTeam Chat for Telegram <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | ninjateam | WP Telegram Chat Widget | Medium | 6.4 | 2024-12-24 05:23:43 | Deep Dive |
| CVE-2024-10390 | Elfsight Telegram Chat CC <= 1.1.0 - Missing Authorization to Authenticated (Subscriber+) Stored Cross-Site Scripting | Elfsight | Elfsight Telegram Chat CC | Medium | 6.4 | 2024-11-18 16:31:32 | Deep Dive |
| CVE-2024-9629 | Contact Form 7 + Telegram <= 0.8.5 - Missing Authorization to Authenticated (Subscriber+) Subscription Approve/Pause/Refuse | hokku | Message Bridge for Contact Form 7 and Telegram | Medium | 5.4 | 2024-10-28 17:31:55 | Deep Dive |
| CVE-2024-9628 | WPS Telegram Chat <= 4.6.0 - Authenticated (Subscriber+) Unauthorized Access to Telegram Bot API | wpsolution | WPS Telegram Chat | Medium | 6.3 | 2024-10-25 07:38:01 | Deep Dive |
| CVE-2024-9630 | WPS Telegram Chat <= 4.6.0 - Missing Authorization to Information Exposure | wpsolution | WPS Telegram Chat | Medium | 5.4 | 2024-10-25 07:38:00 | Deep Dive |
| CVE-2024-9686 | Order Notification for Telegram <= 1.0.1 - Missing Authorization to Unauthenticated Send Telegram Test Message | choplugins | Order Notification for Telegram | Medium | 5.3 | 2024-10-25 04:33:41 | Deep Dive |
| CVE-2024-9627 | TeploBot - Telegram Bot for WP <= 1.3 - Telegram Bot Token Disclosure | gsuvorov | TeploBot – Telegram Bot for WP | High | 8.6 | 2024-10-22 06:50:30 | Deep Dive |
| CVE-2024-9820 | WP 2FA with Telegram <= 3.0 - Two-Factor Authentication Bypass | dueclic | AuthPress | Medium | 6.5 | 2024-10-15 02:03:53 | Deep Dive |