livehelperchat
Communicationsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting livehelperchat.
- CVE-2026-44633Live Helper Chat: REST API chat update accepts arbitrary chat fields across department boundaries8.1
- CVE-2026-27954LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and transferchat endpoints6.5
- CVE-2025-51403A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a ...6.5
- CVE-2025-51401A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload i...5.4
- CVE-2025-51400A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.5.4
- CVE-2025-51398A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted paylo...5.4
- CVE-2025-51397A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload int...5.4
- CVE-2025-51396A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username ...5.4
- CVE-2025-7435LiveHelperChat lhc-php-resque Extension List list cross site scripting3.5
- CVE-2024-27516Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lh...9.8
- CVE-2022-1530Cross-site Scripting (XSS) in livehelperchat/livehelperchat6.1
- CVE-2022-0935Host Header injection in password Reset in livehelperchat/livehelperchat8.8
- CVE-2022-1234XSS in livehelperchat in livehelperchat/livehelperchat6.1
- CVE-2022-1235Weak secrethash can be brute-forced in livehelperchat/livehelperchat8.2
- CVE-2022-1213SSRF filter bypass port 80, 433 in livehelperchat/livehelperchat8.1