quantumcloud kayıtları
quantumcloud üreticisine ait 41 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %29,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-862 Missing Authorization3
- CWE-284 Improper Access Control3
- CWE-502 Deserialization of Untrusted Data2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
41 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
49Planlayın | CVE-2023-1650İstismar yok | ChatBot < 4.4.7 - Unauthenticated PHP Object Injectionquantumcloud · wpbot · CWE-502 | Kritik9,8 | — | %34,4 | 8 May 2023 |
43Planlayın | CVE-2022-0747Kavram kanıtı | Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injectionquantumcloud · infographic maker · CWE-89 | Kritik9,8 | — | %14,9 | 21 Mar 2022 |
42Planlayın | CVE-2022-0760Kavram kanıtı | Simple Link Directory < 7.7.2 - Unauthenticated SQL injectionquantumcloud · simple link directory · CWE-89 | Kritik9,8 | — | %10,8 | 21 Mar 2022 |
39İzleyin | CVE-2024-6809İstismar yok | Simple Video Directory < 1.4.3 - Unauthenticated SQLiquantumcloud · simple video directory · CWE-89 | Kritik9,8 | — | %0,7 | 15 May 2025 |
39İzleyin | CVE-2023-5533İstismar yok | AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actionsquantumcloud · wpbot · CWE-862 | Kritik9,8 | — | %0,5 | 20 Eki 2023 |
39İzleyin | CVE-2024-22309İstismar yok | WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injectionquantumcloud · wpbot · CWE-502 | Kritik9,8 | — | %0,5 | 24 Oca 2024 |
35İzleyin | CVE-2021-24506İstismar yok | Slider Hero < 8.2.7 - Contributor+ SQL Injectionquantumcloud · slider hero · CWE-89 | Yüksek8,8 | — | %1,4 | 23 Ağu 2021 |
35İzleyin | CVE-2023-24415İstismar yok | WordPress AI ChatBot plugin <= 4.2.8 is vulnerable to Cross Site Request Forgery (CSRF)quantumcloud · chatbot · CWE-352 | Yüksek8,8 | — | %0,3 | 23 Şub 2023 |
35İzleyin | CVE-2023-44993İstismar yok | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)quantumcloud · wpbot · CWE-352 | Yüksek8,8 | — | %0,2 | 9 Eki 2023 |
33İzleyin | CVE-2023-5241İstismar yok | AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_filequantumcloud · wpbot · CWE-22 | Yüksek8,1 | — | %2,1 | 19 Eki 2023 |
32İzleyin | CVE-2023-5204Kavram kanıtı | AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_responsequantumcloud · wpbot · CWE-89 | Yüksek7,5 | — | %6,8 | 19 Eki 2023 |
32İzleyin | CVE-2023-5212İstismar yok | AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_filequantumcloud · wpbot · CWE-22 | Yüksek8,1 | — | %1,6 | 19 Eki 2023 |
30İzleyin | CVE-2024-0452İstismar yok | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callbackquantumcloud · wpbot · CWE-284 | Yüksek7,7 | — | %0,4 | 22 May 2024 |
30İzleyin | CVE-2024-0453İstismar yok | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callbackquantumcloud · wpbot · CWE-284 | Yüksek7,7 | — | %0,4 | 22 May 2024 |
28İzleyin | CVE-2023-48741İstismar yok | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injectionquantumcloud · wpbot · CWE-89 | Yüksek7,2 | — | %0,7 | 19 Ara 2023 |
26İzleyin | CVE-2024-32696İstismar yok | WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerabilityquantumcloud · infographic maker – ilist · CWE-79 | Orta6,5 | — | %0,3 | 22 Nis 2024 |
24İzleyin | CVE-2019-13463İstismar yok | An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackersquantumcloud · simple link directory · CWE-79 | Orta6,1 | — | %1,1 | 20 Mar 2020 |
24İzleyin | CVE-2023-1660İstismar yok | ChatBot < 4.4.9 - Unauthenticated Stored XSSquantumcloud · wpbot · CWE-79 | Orta6,1 | — | %0,3 | 8 May 2023 |
24İzleyin | CVE-2023-1011İstismar yok | ChatBot < 4.4.5 - Stored XSS via CSRFquantumcloud · wpbot · CWE-352 | Orta6,1 | — | %0,2 | 8 May 2023 |
21İzleyin | CVE-2023-5254İstismar yok | AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_userquantumcloud · wpbot · CWE-200 | Orta5,3 | — | %0,8 | 19 Eki 2023 |
21İzleyin | CVE-2024-52395İstismar yok | WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerabilityquantumcloud · floating buttons for woocommerce · CWE-862 | Orta5,3 | — | %0,4 | 19 Kas 2024 |
21İzleyin | CVE-2024-5811İstismar yok | Simple Video Directory < 1.4.4 - Contributor+ Stored XSSquantumcloud · simple video directory · CWE-79 | Orta5,4 | — | %0,3 | 12 Tem 2024 |
21İzleyin | CVE-2023-1651İstismar yok | ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSSquantumcloud · wpbot · CWE-79 | Orta5,4 | — | %0,2 | 8 May 2023 |
21İzleyin | CVE-2023-5534İstismar yok | AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actionsquantumcloud · wpbot · CWE-352 | Orta5,4 | — | %0,2 | 20 Eki 2023 |
20İzleyin | CVE-2024-0451İstismar yok | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callbackquantumcloud · wpbot · CWE-284 | Orta5,0 | — | %0,4 | 22 May 2024 |
- CVE-2023-165049Planlayın
ChatBot < 4.4.7 - Unauthenticated PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %34quantumcloud · wpbot8 May 2023
- CVE-2022-074743Planlayın
Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection
KritikCVSS 9,8Kavram kanıtıEPSS %15quantumcloud · infographic maker21 Mar 2022
- CVE-2022-076042Planlayın
Simple Link Directory < 7.7.2 - Unauthenticated SQL injection
KritikCVSS 9,8Kavram kanıtıEPSS %11quantumcloud · simple link directory21 Mar 2022
- CVE-2024-680939İzleyin
Simple Video Directory < 1.4.3 - Unauthenticated SQLi
KritikCVSS 9,8İstismar yokEPSS %1quantumcloud · simple video directory15 May 2025
- CVE-2023-553339İzleyin
AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions
KritikCVSS 9,8İstismar yokEPSS %1quantumcloud · wpbot20 Eki 2023
- CVE-2024-2230939İzleyin
WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection
KritikCVSS 9,8İstismar yokEPSS %1quantumcloud · wpbot24 Oca 2024
- CVE-2021-2450635İzleyin
Slider Hero < 8.2.7 - Contributor+ SQL Injection
YüksekCVSS 8,8İstismar yokEPSS %1quantumcloud · slider hero23 Ağu 2021
- CVE-2023-2441535İzleyin
WordPress AI ChatBot plugin <= 4.2.8 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0quantumcloud · chatbot23 Şub 2023
- CVE-2023-4499335İzleyin
WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)
YüksekCVSS 8,8İstismar yokEPSS %0quantumcloud · wpbot9 Eki 2023
- CVE-2023-524133İzleyin
AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file
YüksekCVSS 8,1İstismar yokEPSS %2quantumcloud · wpbot19 Eki 2023
- CVE-2023-520432İzleyin
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
YüksekCVSS 7,5Kavram kanıtıEPSS %7quantumcloud · wpbot19 Eki 2023
- CVE-2023-521232İzleyin
AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file
YüksekCVSS 8,1İstismar yokEPSS %2quantumcloud · wpbot19 Eki 2023
- CVE-2024-045230İzleyin
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback
YüksekCVSS 7,7İstismar yokEPSS %0quantumcloud · wpbot22 May 2024
- CVE-2024-045330İzleyin
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback
YüksekCVSS 7,7İstismar yokEPSS %0quantumcloud · wpbot22 May 2024
- CVE-2023-4874128İzleyin
WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injection
YüksekCVSS 7,2İstismar yokEPSS %1quantumcloud · wpbot19 Ara 2023
- CVE-2024-3269626İzleyin
WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerability
OrtaCVSS 6,5İstismar yokEPSS %0quantumcloud · infographic maker – ilist22 Nis 2024
- CVE-2019-1346324İzleyin
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers
OrtaCVSS 6,1İstismar yokEPSS %1quantumcloud · simple link directory20 Mar 2020
- CVE-2023-166024İzleyin
ChatBot < 4.4.9 - Unauthenticated Stored XSS
OrtaCVSS 6,1İstismar yokEPSS %0quantumcloud · wpbot8 May 2023
- CVE-2023-101124İzleyin
ChatBot < 4.4.5 - Stored XSS via CSRF
OrtaCVSS 6,1İstismar yokEPSS %0quantumcloud · wpbot8 May 2023
- CVE-2023-525421İzleyin
AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
OrtaCVSS 5,3İstismar yokEPSS %1quantumcloud · wpbot19 Eki 2023
- CVE-2024-5239521İzleyin
WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerability
OrtaCVSS 5,3İstismar yokEPSS %0quantumcloud · floating buttons for woocommerce19 Kas 2024
- CVE-2024-581121İzleyin
Simple Video Directory < 1.4.4 - Contributor+ Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %0quantumcloud · simple video directory12 Tem 2024
- CVE-2023-165121İzleyin
ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSS
OrtaCVSS 5,4İstismar yokEPSS %0quantumcloud · wpbot8 May 2023
- CVE-2023-553421İzleyin
AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions
OrtaCVSS 5,4İstismar yokEPSS %0quantumcloud · wpbot20 Eki 2023
- CVE-2024-045120İzleyin
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback
OrtaCVSS 5,0İstismar yokEPSS %0quantumcloud · wpbot22 May 2024