Extension WordPress
Vulnérabilités Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
Cette page rassemble les failles publiées pour Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty
11 fiches
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.5.1 – Unauthenticated Information Exposure
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.5.1. This makes it…
*-3.5.1
3.5.2
24/02/2026
Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty <= 3.3.5 – Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button, WhatsApp – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘data-hover’ parameter in all versions up to, and…
*-3.3.5
3.3.6
26/02/2025
Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty <= 3.2.2 – Authenticated (Admin+) Stored Cross-Site Scripting
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including,…
*-3.2.2
3.2.3
23/05/2024
Floating Chat Widget <= 3.1.8 – Authenticated (Editor+) Stored Cross-Site Scripting
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the cht_social_Whatsapp[bg_color] parameter in all versions up to, and…
*-3.1.8
3.1.9
03/04/2024
Chaty <= 3.1.2 – Authenticated (Administrator+) Stored Cross-Site Scripting via settings
The Floating Chat Widget: Contact Chat Icons, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.1.2…
*-3.1.2
3.1.3
13/11/2023
Floating Chat Widget – Chaty <= 3.1.1 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Floating Chat Widget – Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.1.1 due to insufficient input sanitization and output escaping. This makes it possible for…
*-3.1.1
3.1.2
26/06/2023
Chaty <= 3.0.9 – Authenticated (Admin+) Stored Cross-Site Scripting
The Chaty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via chat widget settings like 'cht_close_button_text' in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-3.0.9
3.1
16/05/2023
Chaty <= 3.0.9 – Reflected Cross-Site Scripting
The Chaty plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'channel' parameters in versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…
*-3.0.9
3.1
16/05/2023
Floating Chat Widget – Chaty <= 3.0.2 – Authenticated (Administrator+) SQL Injection
The Chaty plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 3.0.2 due to insufficient escaping on the $chaty_leads parameter and lack of sufficient preparation on the existing SQL query. This makes it…
*-3.0.2
3.0.3
14/11/2022
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty <= 2.8.3 – Admin+ Stored Cross-Site Scripting
Authenticated (admin or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in Premio Chaty (WordPress plugin)
*-2.8.3
2.8.5
08/04/2022
Floating Chat Widget: Contact Icons, Messages, Telegram, Email, SMS, Call Button – Chaty <= 2.8.2 Reflected Cross-Site Scripting
The Chaty WordPress plugin before 2.8.3 and Chaty Pro WordPress plugin before 2.8.2 do not sanitise and escape the search parameter before outputting it back in the admin dashboard, leading to a Reflected Cross-Site Scripting
[*, 2.8.3)
2.8.3
06/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.