Typebot

Typebot

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.02%
  • Veröffentlicht 22.01.2026 14:59:20
  • Zuletzt bearbeitet 30.01.2026 14:32:00

Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim previews a malicious typebot by clicking "Run", JavaScript executes in...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 13.11.2025 19:42:42
  • Zuletzt bearbeitet 30.01.2026 14:23:42

Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) functionality allows authenticated users to make arbitrary HTTP requests ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 13.11.2025 17:49:29
  • Zuletzt bearbeitet 30.01.2026 14:14:33

Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token management endpoint. An authenticated attacker can delete any user's API ...

  • EPSS 0.16%
  • Veröffentlicht 20.07.2024 08:15:15
  • Zuletzt bearbeitet 21.11.2024 09:26:45

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Typebot allows Stored XSS.This issue affects Typebot: from n/a through 3.6.0.

Exploit
  • EPSS 0.57%
  • Veröffentlicht 04.04.2024 21:15:16
  • Zuletzt bearbeitet 30.01.2026 14:12:48

Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's account. The sign-in page takes the `redirectPath` parameter from the...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 27.12.2021 11:15:08
  • Zuletzt bearbeitet 21.11.2024 05:53:58

The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capabil...