Known Vulnerabilities for products from Livezilla
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Livezilla".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-9758 json | An issue was discovered in chat.php in LiveZilla Live Chat 8.0.1.3 (Helpdesk). A blind JavaScript injection lies in the name ... | 9.6 - CRITICAL | 2020-03-09 | 2020-03-10 |
| CVE-2019-12964 json | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the ticket.php Subject. | 6.1 - MEDIUM | 2019-06-25 | 2019-06-25 |
| CVE-2019-12963 json | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in the chat.php Create Ticket Action. | 6.1 - MEDIUM | 2019-06-25 | 2019-06-25 |
| CVE-2019-12962 json | LiveZilla Server before 8.0.1.1 is vulnerable to XSS in mobile/index.php via the Accept-Language HTTP header. | 6.1 - MEDIUM | 2019-06-25 | 2021-04-06 |
| CVE-2019-12961 json | LiveZilla Server before 8.0.1.1 is vulnerable to CSV Injection in the Export Function. | 8.8 - HIGH | 2019-06-25 | 2020-08-24 |
| CVE-2019-12960 json | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in functions.internal.build.inc.php via the parameter p_dt_s_d... | 9.8 - CRITICAL | 2019-06-25 | 2019-06-25 |
| CVE-2019-12940 json | LiveZilla Server before 8.0.1.1 is vulnerable to Denial Of Service (memory consumption) in knowledgebase.php via a large inte... | 5.9 - MEDIUM | 2019-06-24 | 2020-08-24 |
| CVE-2019-12939 json | LiveZilla Server before 8.0.1.1 is vulnerable to SQL Injection in server.php via the p_ext_rse parameter. | 9.8 - CRITICAL | 2019-06-24 | 2019-06-26 |
| CVE-2018-10810 json | chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HT... | 6.1 - MEDIUM | 2018-05-16 | 2018-06-19 |
| CVE-2017-15869 json | Cross-site scripting (XSS) vulnerability in knowledgebase.php in LiveZilla before 7.0.8.9 allows remote attackers to inject a... | 6.1 - MEDIUM | 2018-01-18 | 2019-04-29 |
| CVE-2013-7385 json | LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generate... | Not Provided | 2014-05-19 | 2026-05-06 |
| CVE-2013-7034 json | The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute a... | Not Provided | 2014-05-05 | 2026-05-06 |
| CVE-2013-7033 json | LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.p... | Not Provided | 2014-05-19 | 2026-05-06 |
| CVE-2013-7032 json | Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote... | Not Provided | 2014-02-14 | 2026-04-29 |
| CVE-2013-7003 json | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary we... | Not Provided | 2014-05-05 | 2026-05-06 |
| CVE-2013-7002 json | Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attack... | Not Provided | 2013-12-21 | 2026-04-29 |
| CVE-2013-6225 json | LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability | 9.8 - CRITICAL | 2020-01-13 | 2020-01-17 |
| CVE-2013-6224 json | Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary we... | Not Provided | 2013-12-10 | 2026-04-29 |
| CVE-2013-6223 json | LiveZilla before 5.1.1.0 stores the admin Base64 encoded username and password in a 1click file, which allows local users to ... | Not Provided | 2014-06-09 | 2026-05-06 |
| CVE-2010-4276 json | Cross-site scripting (XSS) vulnerability in the lz_tracking_set_sessid function in templates/jscript/jstrack.tpl in LiveZilla... | Not Provided | 2010-12-30 | 2026-04-29 |
Known software with vulnerabilities from Livezilla
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Livezilla | Livezilla | 3.1.8.3 |