Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2020-9758 An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name parameter. Triggering th… Livezilla 8.0.1.3+ Fix from $2,3002020-03-09 CRITICAL 9.8 CVE-2013-6225EPSS 27% LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability Livezilla No fix yet Fix from $2,3002020-01-13 CRITICAL 9.8 CVE-2019-12960 LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d. Livezilla 8.0.1.1+ Fix from $2,3002019-06-25 HIGH 8.8 CVE-2019-12961 LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function. Livezilla 8.0.1.1+ Fix from $1,9502019-06-25 MEDIUM 6.1 CVE-2019-12962EPSS 9% LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. Livezilla 8.0.1.1+ Fix from $1,6002019-06-25 MEDIUM 6.1 CVE-2019-12963 LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action. Livezilla 8.0.1.1+ Fix from $1,6002019-06-25 MEDIUM 6.1 CVE-2019-12964 LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject. Livezilla 8.0.1.1+ Fix from $1,6002019-06-25 CRITICAL 9.8 CVE-2019-12939 LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter. Livezilla 8.0.1.1+ Fix from $2,3002019-06-24 MEDIUM 5.9 CVE-2019-12940 LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large integer value of the depth p… Livezilla 8.0.1.1+ Fix from $1,6002019-06-24 MEDIUM 6.1 CVE-2018-10810 chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header. Livezilla after 7.0.9.5 Fix from $1,6002018-05-16 MEDIUM 6.1 CVE-2017-15869 Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject arbitrary web script or H… Livezilla 7.0.8.9+ Fix from $1,6002018-01-18 MEDIUM 6.8 CVE-2013-7385 LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php,… Livezilla after 5.1.2.1 Fix from $1,6002014-05-19 HIGH 7.5 CVE-2013-7034 The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a … Livezilla after 5.1.2.0 Fix from $1,9502014-05-05