Extension WordPress
Vulnérabilités Crisp – Live Chat and Chatbot
Cette page rassemble les failles publiées pour Crisp – Live Chat and Chatbot, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Crisp – Live Chat and Chatbot
2 fiches
Crisp <= 0.44 – Authenticated (Subscriber+) Stored Cross-Site Scripting
The Crisp plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 0.44 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above,…
*-0.44
0.45
13/03/2024
Crisp Live Chat <= 0.31 Cross-Site Request Forgery to Stored Cross-Site Scripting
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in…
*-0.31
0.32
16/12/2021
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.