汇总 webdigit 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。
常见弱点模式包括 SQL 注入与跨站脚本,在 软件部署与生产负载 使用场景中可能带来 会话劫持与数据泄露 等风险。
相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。
| CVE | 摘要 | 来源 | 最高 CVSS | EPSS % | 公开时间 | 更新时间 |
|---|---|---|---|---|---|---|
| CVE-2024-6845 | The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key | [email protected] | 5.3 | 21.60% | 2024-09-25 | 2026-01-20 |
| CVE-2024-6846 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not validate access on some REST routes, allowing for an unauthenticated user to purge error and chat logs | [email protected] | 5.3 | 6.31% | 2024-09-05 | 2025-05-16 |
| CVE-2024-6847 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot. | [email protected] | 9.8 | 2.15% | 2024-08-20 | 2025-05-27 |
| CVE-2024-6843 | The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not sanitise and escape user inputs, which could allow unauthenticated users to perform Stored Cross-Site Scripting attacks against admins | [email protected] | 6.1 | 1.80% | 2024-08-19 | 2025-05-27 |