Where
-Infinity
0

Vendor Risk Score

See how typebot compares to other vendors in security performance

View Risk Score →

Typebot TypebotTypeBot API tokens stored in plaintext

Risk 54
First published (updated )

Typebot TypebotTypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution

Risk 60
Severity
8.1
First published (updated )

Typebot TypebotTypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass

Risk 54
Severity
8.2
First published (updated )

Typebot TypebotTypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName

Risk 61
Severity
9.3
First published (updated )

Typebot TypebotTypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typebot TypebotTypeBot: WhatsApp Webhook Endpoint Missing Signature Verification

Risk 40
Severity
6.5
First published (updated )

Typebot TypebotTypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter

Risk 17
Severity
3.1
First published (updated )

Typebot TypebotTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint

Risk 48
Severity
7.1
First published (updated )

Typebot TypebotTypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and leaking cross-workspace bot definitions

Risk 38
Severity
6.5
First published (updated )

Typebot TypebotTypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture Form

Risk 59
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typebot TypebotTypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks

Risk 44
Severity
7.7
First published (updated )

Typebot TypebotTypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on visitors' browsers

Risk 34
Severity
5.4
First published (updated )

Typebot TypebotTypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Validation

Risk 58
Severity
7.6
First published (updated )

Typebot TypebotTypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSRF controls

Risk 73
Severity
10
First published (updated )

Typebot Typebot (embed package)Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Preview

Risk 61
Severity
8.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typebot TypebotTypebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure

Risk 38
Severity
6.5
First published (updated )

npm/typebotTypebot Vulnerable to Credential Theft via Client-Side Script Execution and API Authorization Bypass

Risk 42
Severity
7.4
First published (updated )

Typebot TypebotTypebot May Expose AWS EKS Credentials via Server Side Request Forgery in Webhook Block

Risk 82
Severity
9.9
First published (updated )

Typebot TypebotTypebot IDOR Vulnerability: Unauthorized API Token Deletion and Exposure

Risk 70
Severity
7.5
First published (updated )

Typebot TypebotWordPress Typebot plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability

Risk 46
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Typebot Typebottypebot.io: `GHSL-2024-040`

Risk 47
Severity
9.3
EPSS
0.04%
First published (updated )

Typebot Typebot WordpressTypebot < 1.4.3 - Admin+ Stored Cross Site Scripting

Risk 29
Severity
4.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203