Typebot is a conversational form and chatbot platform with a narrow but strategically exposed footprint, where its vulnerability profile concentrates around web application input handling and access control. The recurring weakness classes—cross-site scripting, authorization bypass through user-controlled keys, improper access control, credential exposure, and information disclosure—reflect the authentication and trust-boundary challenges inherent to a multi-tenant web platform. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Typebot over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-64709CRITICAL Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerability in the Typebot webhook block (HTTP Request component) fun | Nov 13, 2025 | 9.9 | 33 | NO | NO |
CVE-2025-65098HIGH Typebot is an open-source chatbot builder. In versions prior to 3.13.2, client-side script execution in Typebot allows stealing all stored credentials from any user. When a victim | Jan 22, 2026 | 7.4 | 28 | NO | NO |
CVE-2024-30264CRITICAL Typebot is an open-source chatbot builder. A reflected cross-site scripting (XSS) in the sign-in page of typebot.io prior to version 2.24.0 may allow an attacker to hijack a user's | Apr 4, 2024 | 9.3 | 26 | NO | NO |
CVE-2025-64706HIGH Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API token man | Nov 13, 2025 | 7.5 | 24 | NO | NO |
CVE-2024-38757MEDIUM Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Typebot allows Stored XSS.This issue affects Typebot: from n/a through | Jul 20, 2024 | 6.5 | 19 | NO | NO |
CVE-2021-24902MEDIUM The Typebot | Build beautiful conversational forms WordPress plugin before 1.4.3 does not sanitise and escape the Publish ID setting, which could allow high privilege users to perf | Dec 27, 2021 | 4.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Typebot.
Media articles that mention a CVE ID that affects a product developed by Typebot — matched by CVE ID, not by vendor name.