| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-32964 | lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability | lobehub | lobe-chat | Critical | 9.0 | 2024-05-10 14:49:31 | Deep Dive |
| CVE-2024-3595 | Pure Chat – Live Chat Plugin & More! <= 2.22 - Authenticated (Subscriber+) Stored Cross-Site Scripting | pure-chat | Pure Chat – Live Chat & More! | Medium | 6.4 | 2024-05-09 20:03:29 | Deep Dive |
| CVE-2024-3849 | Click to Chat – HoliThemes <= 3.35 - Authenticated (Contributor+) Local File Inclusion | holithemes | Click to Chat – HoliThemes | High | 8.8 | 2024-05-02 16:52:55 | Deep Dive |
| CVE-2024-2837 | WP Chat App < 3.6.4 - Admin+ Stored XSS | Unknown | WP Chat App | - | - | 2024-04-26 05:00:03 | Deep Dive |
| CVE-2024-2972 | Floating Chat Widget < 3.1.9 - Editor+ Stored XSS | Unknown | Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button | 中危 | - | 2024-04-24 05:00:03 | Deep Dive |
| CVE-2024-2513 | WP Chat App <= 3.6.2 - Authenticated(Contributor+) Stored Cross-Site Scripting via Block Image Attribute | ninjateam | WP Chat App | Medium | 6.4 | 2024-04-09 18:58:44 | Deep Dive |
| CVE-2024-31258 | WordPress Form to Chat App plugin <= 1.1.6 - Cross Site Scripting (XSS) vulnerability | Micro.company | Form to Chat App | Medium | 6.5 | 2024-04-07 17:44:40 | Deep Dive |
| CVE-2024-20367 | Cisco Enterprise Chat and Email 安全漏洞 | Cisco | Cisco Enterprise Chat and Email | Medium | 5.4 | 2024-04-03 16:22:23 | Deep Dive |
| CVE-2024-31108 | WordPress iFlyChat plugin <= 4.7.2 - Cross Site Scripting (XSS) vulnerability | iFlyChat Team | iFlyChat – WordPress Chat | Medium | 6.5 | 2024-03-31 18:59:55 | Deep Dive |
| CVE-2024-30436 | WordPress Collect.chat plugin <= 2.4.1 - Cross Site Scripting (XSS) vulnerability | Collect.chat Inc. | Collectchat | Medium | 6.5 | 2024-03-29 17:25:05 | Deep Dive |
| CVE-2024-29789 | WordPress OneClick Chat to Order plugin <= 1.0.5 - Cross Site Scripting (XSS) vulnerability | Walter Pinem | OneClick Chat to Order | Medium | 6.5 | 2024-03-27 12:44:49 | Deep Dive |
| CVE-2024-2956 | Simple Ajax Chat <= 20231101 - Authenticated (Admin+) Stored Cross-Site Scripting | specialk | Simple Ajax Chat – Add a Fast, Secure Chat Box | Medium | 4.4 | 2024-03-27 07:34:52 | Deep Dive |
| CVE-2024-1983 | Simple Ajax Chat < 20240223 - Unauthenticated Stored XSS | Unknown | Simple Ajax Chat | - | - | 2024-03-20 05:00:03 | Deep Dive |
| CVE-2024-0898 | Chat Bubble <= 2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting | bluecoral | Chat Bubble – Floating Chat with Contact Chat Icons, Messages, Telegram, Email, SMS, Call me back | Medium | 4.4 | 2024-03-13 15:27:09 | Deep Dive |
| CVE-2024-0447 | ArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 - Missing Authorization to Settings Update | artibot | ArtiBot Free Chat Bot for WebSites | Medium | 5.0 | 2024-03-13 15:27:02 | Deep Dive |
| CVE-2024-0449 | ArtiBot Free Chat Bot for WordPress WebSites <= 1.1.6 - Authenticated (Admin+) Cross-Site Scripting | artibot | ArtiBot Free Chat Bot for WebSites | Medium | 4.4 | 2024-03-13 15:26:46 | Deep Dive |
| CVE-2024-1761 | WP Chat App <= 3.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Block Attributes | ninjateam | WP Chat App | Medium | 6.4 | 2024-03-07 04:31:36 | Deep Dive |
| CVE-2023-37540 | HCL Sametime Chat is affected by an unimplemented feature in the UI | HCL Software | HCL Sametime Chat | Low | 3.9 | 2024-02-23 07:00:59 | Deep Dive |
| CVE-2023-51370 | WordPress WP Chat App Plugin <= 3.4.4 is vulnerable to Cross Site Scripting (XSS) | NinjaTeam | WP Chat App | Medium | 5.9 | 2024-02-12 06:46:18 | Deep Dive |
| CVE-2024-24566 | Lobe Chat unauthorized access to plugins | lobehub | lobe-chat | Medium | 5.3 | 2024-01-31 16:33:44 | Deep Dive |