Livehelperchat
Source repositories
CVEs (43)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0374 | Med | 0.28 | 5.4 | 0.01 | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0253 | Med | 0.28 | 5.4 | 0.01 | Jan 17, 2022 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2022-0083 | Med | 0.28 | 5.3 | 0.01 | Jan 4, 2022 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | ||
| CVE-2021-4132 | Med | 0.28 | 5.4 | 0.01 | Dec 17, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2022-0375 | Med | 0.24 | 4.8 | 0.01 | Jan 26, 2022 | Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v. | ||
| CVE-2022-0245 | Med | 0.21 | 4.3 | 0.00 | Jan 18, 2022 | Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0. | ||
| CVE-2022-0226 | Med | 0.21 | 4.3 | 0.00 | Jan 14, 2022 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2025-51403 | Med | 0.03 | 6.5 | 0.02 | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter. | ||
| CVE-2025-51401 | Med | 0.03 | 5.4 | 0.01 | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter. | ||
| CVE-2025-51400 | Med | 0.03 | 5.4 | 0.01 | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload. | ||
| CVE-2025-51398 | Med | 0.03 | 5.4 | 0.01 | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter. | ||
| CVE-2025-51397 | Med | 0.03 | 5.4 | 0.01 | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists. | ||
| CVE-2025-51396 | Med | 0.03 | 5.4 | 0.01 | Jul 21, 2025 | A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter. | ||
| CVE-2022-0935 | Hig | 0.00 | 8.8 | 0.01 | Apr 7, 2022 | Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97. | ||
| CVE-2022-1234 | Med | 0.00 | 6.1 | 0.01 | Apr 6, 2022 | XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device. | ||
| CVE-2022-1191 | Hig | 0.00 | 8.1 | 0.01 | Mar 31, 2022 | SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96. | ||
| CVE-2021-4176 | Med | 0.00 | 6.1 | 0.01 | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4175 | Med | 0.00 | 5.4 | 0.01 | Dec 29, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4179 | Med | 0.00 | 5.4 | 0.00 | Dec 28, 2021 | livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2021-4177 | Med | 0.00 | 5.3 | 0.01 | Dec 28, 2021 | livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information |
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- risk 0.28cvss 5.4epss 0.01
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.28cvss 5.3epss 0.01
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
- risk 0.28cvss 5.4epss 0.01
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.24cvss 4.8epss 0.01
Cross-site Scripting (XSS) - Stored in Packagist remdex/livehelperchat prior to 3.93v.
- risk 0.21cvss 4.3epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository livehelperchat/livehelperchat prior to 2.0.
- risk 0.21cvss 4.3epss 0.00
livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.03cvss 6.5epss 0.02
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.
- risk 0.03cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
- risk 0.03cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
- risk 0.03cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
- risk 0.03cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
- risk 0.03cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.
- risk 0.00cvss 8.8epss 0.01
Host Header injection in password Reset in GitHub repository livehelperchat/livehelperchat prior to 3.97.
- risk 0.00cvss 6.1epss 0.01
XSS in livehelperchat in GitHub repository livehelperchat/livehelperchat prior to 3.97. This vulnerability has the potential to deface websites, result in compromised user accounts, and can run malicious code on web pages, which can lead to a compromise of the user’s device.
- risk 0.00cvss 8.1epss 0.01
SSRF on index.php/cobrowse/proxycss/ in GitHub repository livehelperchat/livehelperchat prior to 3.96.
- risk 0.00cvss 6.1epss 0.01
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 5.4epss 0.01
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 5.4epss 0.00
livehelperchat is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 5.3epss 0.01
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
Page 2 of 3