VYPR

Crisp

by Crisp

CVEs (2)

  • CVE-2021-43353HigJan 18, 2022
    risk 0.57cvss 8.8epss 0.01

    The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and…

  • CVE-2024-27963MedMar 21, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.