VendorsLive Helper Chatlive_helper_chatany version
Vulnerabilities

Live Helper Chat Live Helper Chat any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2024-27516
Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.
Published 2024-02-28 · Analyzed
9.8EPSS 0.015
CVE-2022-0935
Host Header injection in password Reset in livehelperchat/livehelperchat
Published 2022-04-07 · Modified
8.8EPSS 0.013
CVE-2022-1234
XSS in livehelperchat in livehelperchat/livehelperchat
Published 2022-04-06 · Modified
8.8EPSS 0.007
CVE-2021-4131
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Published 2021-12-18 · Modified
8.8EPSS 0.005
CVE-2022-1191
SSRF on index.php/cobrowse/proxycss/ in livehelperchat/livehelperchat
Published 2022-03-31 · Modified
8.7EPSS 0.010
CVE-2022-1235
Weak secrethash can be brute-forced in livehelperchat/livehelperchat
Published 2022-04-05 · Modified
8.2EPSS 0.006
CVE-2022-1213
SSRF filter bypass port 80, 433 in livehelperchat/livehelperchat
Published 2022-04-05 · Modified
8.1EPSS 0.006
CVE-2022-1176
Loose comparison causes IDOR on multiple endpoints in livehelperchat/livehelperchat
Published 2022-03-31 · Modified
7.5EPSS 0.013
CVE-2022-0083
Generation of Error Message Containing Sensitive Information in livehelperchat/livehelperchat
Published 2022-01-04 · Modified
7.3EPSS 0.009
CVE-2021-4132
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2021-12-17 · Modified
7.3EPSS 0.006
CVE-2022-0612
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2022-02-16 · Modified
6.7EPSS 0.006
CVE-2022-0266
Authorization Bypass Through User-Controlled Key in livehelperchat/livehelperchat
Published 2022-01-19 · Modified
6.6EPSS 0.011
CVE-2021-4175
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2021-12-29 · Modified
6.6EPSS 0.005
CVE-2021-4179
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2021-12-28 · Modified
6.6EPSS 0.005
CVE-2025-51403
A stored cross-site scripting (XSS) vulnerability in the department assignment editing module of of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Alias Nick parameter.
Published 2025-07-21 · Analyzed
6.51 PoCEPSS 0.015
CVE-2022-0375
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2022-01-26 · Modified
6.5EPSS 0.007
CVE-2022-0374
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2022-01-26 · Modified
6.5EPSS 0.007
CVE-2022-0395
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2022-01-28 · Modified
6.5EPSS 0.006
CVE-2022-0502
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2022-02-06 · Modified
6.5EPSS 0.006
CVE-2022-0231
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Published 2022-01-14 · Modified
6.5EPSS 0.005
CVE-2021-4123
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Published 2021-12-16 · Modified
6.5EPSS 0.005
CVE-2021-4049
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Published 2021-12-07 · Modified
6.5EPSS 0.004
CVE-2026-27954
LiveHelperChat has department-level authorization bypass in holdaction, blockuser, and transferchat endpoints
Published 2026-02-26 · Analyzed
6.5EPSS 0.003
CVE-2017-1000059
Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.
Published 2017-07-13 · Modified
6.1EPSS 0.011
CVE-2020-26134
Live Helper Chat before 3.44v allows stored XSS in chat messages with an operator via BBCode.
Published 2020-10-02 · Modified
6.1EPSS 0.011
CVE-2020-26135
Live Helper Chat before 3.44v allows reflected XSS via the setsettingajax PATH_INFO.
Published 2020-10-02 · Modified
6.1EPSS 0.010
CVE-2021-4169
Cross-site Scripting (XSS) - Reflected in livehelperchat/livehelperchat
Published 2021-12-26 · Modified
6.1EPSS 0.009
CVE-2021-4050
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2021-12-08 · Modified
6.1EPSS 0.009
CVE-2021-4176
Cross-site Scripting (XSS) - Reflected in livehelperchat/livehelperchat
Published 2021-12-29 · Modified
6.1EPSS 0.008
CVE-2022-1530
Cross-site Scripting (XSS) in livehelperchat/livehelperchat
Published 2022-04-29 · Modified
6.1EPSS 0.007
CVE-2025-51396
A stored cross-site scripting (XSS) vulnerability in Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Telegram Bot Username parameter.
Published 2025-07-21 · Analyzed
5.41 PoCEPSS 0.010
CVE-2025-51397
A stored cross-site scripting (XSS) vulnerability in the Facebook Chat module of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Surname parameter under the Recipient' Lists.
Published 2025-07-21 · Analyzed
5.41 PoCEPSS 0.009
CVE-2025-51398
A stored cross-site scripting (XSS) vulnerability in the Facebook registration page of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.
Published 2025-07-21 · Analyzed
5.41 PoCEPSS 0.009
CVE-2025-51400
A stored cross-site scripting (XSS) vulnerability in the Personal Canned Messages of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.
Published 2025-07-21 · Analyzed
5.41 PoCEPSS 0.009
CVE-2025-51401
A stored cross-site scripting (XSS) vulnerability in the chat transfer function of Live Helper Chat v4.60 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the operator name parameter.
Published 2025-07-21 · Analyzed
5.41 PoCEPSS 0.009
CVE-2022-0394
Cross-site Scripting (XSS) - Stored in livehelperchat/livehelperchat
Published 2022-01-28 · Modified
5.4EPSS 0.005
CVE-2021-4177
Generation of Error Message Containing Sensitive Information in livehelperchat/livehelperchat
Published 2021-12-28 · Modified
5.3EPSS 0.009
CVE-2022-0226
Cross-Site Request Forgery (CSRF) in livehelperchat/livehelperchat
Published 2022-01-14 · Modified
4.3EPSS 0.004