Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

3cx HIGH 7.8
CVE-2023-27362

3CX Uncontrolled Search Path Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected i…

Fix: 18.0.8.917+
Fix from $1,950 2024-05-03
3cx CRITICAL 9.8
CVE-2023-49954

The CRM Integration in 3CX before 18.0.9.23 and 20 before 20.0.0.1494 allows SQL Injection via a first name, search string, or email address.

Fix: 18.0.9.23 / 20.0.0.1494+
Fix from $2,300 2023-12-25
3cx HIGH 7.5
CVE-2022-48483

3CX before 18 Hotfix 1 build 18.0.3.461 on Windows allows unauthenticated remote attackers to read %WINDIR%\system32 files via /Electron/download dir…

Fix: 18.0.3.461+
Fix from $1,950 2023-05-02
3cx HIGH 7.5
CVE-2022-48482

3CX before 18 Update 2 Security Hotfix build 18.0.2.315 on Windows allows unauthenticated remote attackers to read certain files via /Electron/downlo…

Fix: 18.0.2.315+
Fix from $1,950 2023-05-02
3cx HIGH 7.8
CVE-2023-29059

3CX DesktopApp through 18.12.416 has embedded malicious code, as exploited in the wild in March 2023. This affects versions 18.12.407 and 18.12.416 o…

No fix yet
Fix from $1,950 2023-03-30
3cx CRITICAL 9.8
CVE-2022-28005EPSS 6%

An issue was discovered in the 3CX Phone System Management Console prior to version 18 Update 3 FINAL. An unauthenticated attacker could abuse improp…

Fix: after 18.0.3.450
Fix from $2,300 2022-05-06
3cx CRITICAL 9.1
CVE-2021-45490

The client applications in 3CX on Windows, the 3CX app for iOS, and the 3CX application for Android through 2022-03-17 lack SSL certificate validatio…

Fix: after 2022-03-17
Fix from $2,300 2022-03-28
3cx MEDIUM 6.5
CVE-2021-45491

3CX System through 2022-03-17 stores cleartext passwords in a database.

Fix: after 2022-03-17
Fix from $1,600 2022-03-28
Live Chat CRITICAL 9.8
CVE-2019-12498

The WP Live Chat Support plugin before 8.0.33 for WordPress accepts certain REST API calls without invoking the wplc_api_permission_check protection …

Fix: 8.0.33+
Fix from $2,300 2020-03-20
Live Chat MEDIUM 6.1
CVE-2014-10386

The wp-live-chat-support plugin before 4.1.0 for WordPress has JavaScript injections.

Fix: 4.1.0+
Fix from $1,600 2019-08-22
Live Chat MEDIUM 6.1
CVE-2017-18507

The wp-live-chat-support plugin before 7.1.05 for WordPress has XSS.

Fix: 7.1.05+
Fix from $1,600 2019-08-13
Live Chat MEDIUM 6.1
CVE-2019-14950

The wp-live-chat-support plugin before 8.0.27 for WordPress has XSS via the GDPR page.

Fix: 8.0.27+
Fix from $1,600 2019-08-12
Live Chat MEDIUM 6.1
CVE-2016-10879

The wp-live-chat-support plugin before 6.2.02 for WordPress has XSS.

Fix: 6.2.02+
Fix from $1,600 2019-08-12
Live Chat MEDIUM 6.1
CVE-2017-18508

The wp-live-chat-support plugin before 7.1.03 for WordPress has XSS.

Fix: 7.1.03+
Fix from $1,600 2019-08-12
3cx HIGH 7.8
CVE-2019-14935

3CX Phone 15 on Windows has insecure permissions on the "%PROGRAMDATA%\3CXPhone for Windows\PhoneApp" installation directory, allowing Full Control a…

No fix yet
Fix from $1,950 2019-08-12
3cx HIGH 7.5
CVE-2019-13176

An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affe…

No fix yet
Fix from $1,950 2019-08-08
Live Chat CRITICAL 9.8
CVE-2019-11185

The WP Live Chat Support Pro plugin through 8.0.26 for WordPress contains an arbitrary file upload vulnerability. This results from an incomplete pat…

Fix: 8.0.26+
Fix from $2,300 2019-06-03
Live Chat MEDIUM 6.1
CVE-2019-9913

The wp-live-chat-support plugin before 8.0.18 for WordPress has wp-admin/admin.php?page=wplivechat-menu-gdpr-page term XSS.

Fix: 8.0.18+
Fix from $1,600 2019-03-22
Live Chat MEDIUM 6.1
CVE-2018-18460

XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-g…

No fix yet
Fix from $1,600 2018-10-18
3cx Web Server MEDIUM 6.1
CVE-2018-14905

The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter.

No fix yet
Fix from $1,600 2018-08-03
3cx Web Server MEDIUM 6.1
CVE-2018-14906

The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters.

No fix yet
Fix from $1,600 2018-08-03
3cx Web Server MEDIUM 5.3
CVE-2018-14907

The Web server in 3CX version 15.5.8801.3 is vulnerable to Information Leakage, because of improper error handling in Stack traces, as demonstrated b…

No fix yet
Fix from $1,600 2018-08-03
Live Chat CRITICAL 9.8
CVE-2018-12426EPSS 5%

The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation …

Fix: 8.0.07+
Fix from $2,300 2018-07-02
Live Chat MEDIUM 6.1
CVE-2018-11105

There is stored cross site scripting in the wp-live-chat-support plugin before 8.0.08 for WordPress via the "name" (aka wplc_name) and "email" (aka w…

Fix: 8.0.08+
Fix from $1,600 2018-05-15
Live Chat MEDIUM 6.1
CVE-2018-9864

The WP Live Chat Support plugin before 8.0.06 for WordPress has stored XSS via the Name field.

Fix: 8.0.06+
Fix from $1,600 2018-04-09
3cx MEDIUM 6.5
CVE-2018-7654

On 3CX 15.5.6354.2 devices, the parameter "file" in the request "/api/RecordingList/download?file=" allows full access to files on the server via pat…

Mitigation only
Fix from $1,600 2018-03-04
3cx MEDIUM 6.5
CVE-2017-15359EPSS 6%

In the 3CX Phone System 15.5.3554.1, the Management Console typically listens to port 5001 and is prone to a directory traversal attack: "/api/Record…

No fix yet
Fix from $1,600 2017-10-18
Live Chat MEDIUM 6.1
CVE-2017-2187

Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via…

Fix: after 7.0.06
Fix from $1,600 2017-06-09
Phone System HIGH 7.8
CVE-2008-6895

3CX Phone System 6.0.806.0 allows remote attackers to cause a denial of service (unstable service or crash) via unspecified vectors, as demonstrated …

Mitigation only
Fix from $1,950 2009-08-03
Phone System MEDIUM 5.0
CVE-2008-6896

login.php in 3CX Phone System 6.0.806.0, when 100% disk capacity is reached, allows remote attackers to gain sensitive information via unspecified ve…

Mitigation only
Fix from $1,600 2009-08-03