← Back

Crisp

crisp

2 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Crisp
crisp

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Crisp
1Crisp
Jun 17, 2026
Mar 21, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crisp allows Stored XSS.This issue affects Crisp: from n/a through 0.44.
1Crisp
1Crisp
Jun 17, 2026
Jan 18, 2022
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attac...Show more
The Crisp Live Chat WordPress plugin is vulnerable to Cross-Site Request Forgery due to missing nonce validation via the crisp_plugin_settings_page function found in the ~/crisp.php file, which made it possible for attackers to inject arbitrary web scripts in versions up to, and including 0.31.Show less