| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-35249 | Rocket.Chat 信息泄露漏洞 | - | Rocket.Chat | 中危 | - | 2022-09-23 18:28:12 | Deep Dive |
| CVE-2022-35250 | Rocket.Chat 安全漏洞 | - | Rocket.chat | 中危 | - | 2022-09-23 18:28:12 | Deep Dive |
| CVE-2022-35251 | Rocket.Chat 跨站脚本漏洞 | - | Rocket.chat | 中危 | - | 2022-09-23 18:28:12 | Deep Dive |
| CVE-2022-36057 | Discourse-Chat Cross-Site Scripting issue for channel names and descriptions | discourse | discourse-chat | Medium | 5.4 | 2022-09-06 19:30:14 | Deep Dive |
| CVE-2022-2375 | WP Sticky Button < 1.4.1 - Unauthenticated Arbitrary Settings Update to Stored XSS | Unknown | WP Sticky Button – Click to Chat | 中危 | - | 2022-08-22 15:01:53 | Deep Dive |
| CVE-2022-2361 | Social Chat < 6.0.5 - Admin+ Stored Cross-Site Scripting | Unknown | WP Social Chat – Click To Chat App | 中危 | - | 2022-08-22 15:01:30 | Deep Dive |
| CVE-2022-2039 | Free Live Chat Support <= 1.0.11 - Cross-Site Request Forgery to Cross-Site Scripting | livesupporti | Free Live Chat Support | High | 8.8 | 2022-07-18 16:12:50 | Deep Dive |
| CVE-2022-31095 | Exposure of Sensitive Information in discourse-chat | discourse | discourse-chat | Medium | 4.3 | 2022-06-21 19:00:17 | Deep Dive |
| CVE-2022-31013 | Authentication bypass in Vartalap chat-server | ramank775 | chat-server | Critical | 9.1 | 2022-05-31 22:35:11 | Deep Dive |
| CVE-2022-0642 | JivoChat < 1.3.5.4 - Stored Cross-Site Scripting via CSRF | Unknown | JivoChat Live Chat – WP live chat plugin for WordPress | 中危 | - | 2022-05-30 08:35:35 | Deep Dive |
| CVE-2022-20802 | Cisco Enterprise Chat and Email Stored Cross-Site Scripting Vulnerability | Cisco | Cisco Enterprise Chat and Email | Medium | 5.4 | 2022-05-27 14:06:34 | Deep Dive |
| CVE-2022-1239 | HubSpot < 8.8.15 - Contributor+ Blind SSRF | Unknown | HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics | 高危 | - | 2022-05-02 16:05:49 | Deep Dive |
| CVE-2022-27850 | WordPress Simple Ajax Chat plugin <= 20220115 - Multiple Cross-Site Request Forgery (CSRF) vulnerability | Jeff Starr | Simple Ajax Chat (WordPress plugin) | Medium | 5.4 | 2022-04-15 16:24:46 | Deep Dive |
| CVE-2022-27849 | WordPress Simple Ajax Chat plugin <= 20220115 - Sensitive Information Disclosure vulnerability | Jeff Starr | Simple Ajax Chat (WordPress plugin) | Medium | 5.3 | 2022-04-15 16:24:45 | Deep Dive |
| CVE-2022-21830 | RocketChat LiveChat 跨站脚本漏洞 | - | Rocket.chat Livechat | 中危 | - | 2022-04-01 22:17:01 | Deep Dive |
| CVE-2022-25610 | WordPress Simple Ajax Chat plugin <= 20220115 - Unauthenticated Stored Cross-Site Scripting (XSS) vulnerability | Jeff Starr | Simple Ajax Chat (WordPress plugin) | Low | 3.4 | 2022-03-25 18:02:34 | Deep Dive |
| CVE-2022-0148 | All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS) | Unknown | All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements | 中危 | - | 2022-02-07 15:47:25 | Deep Dive |
| CVE-2021-43353 | Crisp Live Chat <= 0.31 Cross-Site Request Forgery to Stored Cross-Site Scripting | Crisp Live Chat | Crisp Live Chat | High | 8.8 | 2022-01-18 16:52:24 | Deep Dive |
| CVE-2022-21649 | Stored XSS via attribute in convos | convos-chat | convos | High | 7.6 | 2022-01-04 20:40:20 | Deep Dive |
| CVE-2022-21650 | Stored XSS via html file upload in convos | convos-chat | convos | High | 7.6 | 2022-01-04 20:40:14 | Deep Dive |