quantumcloud records
41 published records for vendor quantumcloud.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 29.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')6
- CWE-862 Missing Authorization3
- CWE-284 Improper Access Control3
- CWE-502 Deserialization of Untrusted Data2
The weakness classes this vendor ships most often: where to look.
CWEAll records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
49Plan | CVE-2023-1650No exploit | ChatBot < 4.4.7 - Unauthenticated PHP Object Injectionquantumcloud · wpbot · CWE-502 | Critical9.8 | — | 34.4% | May 8, 2023 |
43Plan | CVE-2022-0747Proof of concept | Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injectionquantumcloud · infographic maker · CWE-89 | Critical9.8 | — | 14.9% | Mar 21, 2022 |
42Plan | CVE-2022-0760Proof of concept | Simple Link Directory < 7.7.2 - Unauthenticated SQL injectionquantumcloud · simple link directory · CWE-89 | Critical9.8 | — | 10.8% | Mar 21, 2022 |
39Monitor | CVE-2024-6809No exploit | Simple Video Directory < 1.4.3 - Unauthenticated SQLiquantumcloud · simple video directory · CWE-89 | Critical9.8 | — | 0.7% | May 15, 2025 |
39Monitor | CVE-2023-5533No exploit | AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actionsquantumcloud · wpbot · CWE-862 | Critical9.8 | — | 0.5% | Oct 20, 2023 |
39Monitor | CVE-2024-22309No exploit | WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injectionquantumcloud · wpbot · CWE-502 | Critical9.8 | — | 0.5% | Jan 24, 2024 |
35Monitor | CVE-2021-24506No exploit | Slider Hero < 8.2.7 - Contributor+ SQL Injectionquantumcloud · slider hero · CWE-89 | High8.8 | — | 1.4% | Aug 23, 2021 |
35Monitor | CVE-2023-24415No exploit | WordPress AI ChatBot plugin <= 4.2.8 is vulnerable to Cross Site Request Forgery (CSRF)quantumcloud · chatbot · CWE-352 | High8.8 | — | 0.3% | Feb 23, 2023 |
35Monitor | CVE-2023-44993No exploit | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)quantumcloud · wpbot · CWE-352 | High8.8 | — | 0.2% | Oct 9, 2023 |
33Monitor | CVE-2023-5241No exploit | AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_filequantumcloud · wpbot · CWE-22 | High8.1 | — | 2.1% | Oct 19, 2023 |
32Monitor | CVE-2023-5204Proof of concept | AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_responsequantumcloud · wpbot · CWE-89 | High7.5 | — | 6.8% | Oct 19, 2023 |
32Monitor | CVE-2023-5212No exploit | AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_filequantumcloud · wpbot · CWE-22 | High8.1 | — | 1.6% | Oct 19, 2023 |
30Monitor | CVE-2024-0452No exploit | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callbackquantumcloud · wpbot · CWE-284 | High7.7 | — | 0.4% | May 22, 2024 |
30Monitor | CVE-2024-0453No exploit | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callbackquantumcloud · wpbot · CWE-284 | High7.7 | — | 0.4% | May 22, 2024 |
28Monitor | CVE-2023-48741No exploit | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injectionquantumcloud · wpbot · CWE-89 | High7.2 | — | 0.7% | Dec 19, 2023 |
26Monitor | CVE-2024-32696No exploit | WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerabilityquantumcloud · infographic maker – ilist · CWE-79 | Medium6.5 | — | 0.3% | Apr 22, 2024 |
24Monitor | CVE-2019-13463No exploit | An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackersquantumcloud · simple link directory · CWE-79 | Medium6.1 | — | 1.1% | Mar 20, 2020 |
24Monitor | CVE-2023-1660No exploit | ChatBot < 4.4.9 - Unauthenticated Stored XSSquantumcloud · wpbot · CWE-79 | Medium6.1 | — | 0.3% | May 8, 2023 |
24Monitor | CVE-2023-1011No exploit | ChatBot < 4.4.5 - Stored XSS via CSRFquantumcloud · wpbot · CWE-352 | Medium6.1 | — | 0.2% | May 8, 2023 |
21Monitor | CVE-2023-5254No exploit | AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_userquantumcloud · wpbot · CWE-200 | Medium5.3 | — | 0.8% | Oct 19, 2023 |
21Monitor | CVE-2024-52395No exploit | WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerabilityquantumcloud · floating buttons for woocommerce · CWE-862 | Medium5.3 | — | 0.4% | Nov 19, 2024 |
21Monitor | CVE-2024-5811No exploit | Simple Video Directory < 1.4.4 - Contributor+ Stored XSSquantumcloud · simple video directory · CWE-79 | Medium5.4 | — | 0.3% | Jul 12, 2024 |
21Monitor | CVE-2023-1651No exploit | ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSSquantumcloud · wpbot · CWE-79 | Medium5.4 | — | 0.2% | May 8, 2023 |
21Monitor | CVE-2023-5534No exploit | AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actionsquantumcloud · wpbot · CWE-352 | Medium5.4 | — | 0.2% | Oct 20, 2023 |
20Monitor | CVE-2024-0451No exploit | AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callbackquantumcloud · wpbot · CWE-284 | Medium5.0 | — | 0.4% | May 22, 2024 |
- CVE-2023-165049Plan
ChatBot < 4.4.7 - Unauthenticated PHP Object Injection
CriticalCVSS 9.8No exploitEPSS 34%quantumcloud · wpbotMay 8, 2023
- CVE-2022-074743Plan
Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection
CriticalCVSS 9.8Proof of conceptEPSS 15%quantumcloud · infographic makerMar 21, 2022
- CVE-2022-076042Plan
Simple Link Directory < 7.7.2 - Unauthenticated SQL injection
CriticalCVSS 9.8Proof of conceptEPSS 11%quantumcloud · simple link directoryMar 21, 2022
- CVE-2024-680939Monitor
Simple Video Directory < 1.4.3 - Unauthenticated SQLi
CriticalCVSS 9.8No exploitEPSS 1%quantumcloud · simple video directoryMay 15, 2025
- CVE-2023-553339Monitor
AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions
CriticalCVSS 9.8No exploitEPSS 1%quantumcloud · wpbotOct 20, 2023
- CVE-2024-2230939Monitor
WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection
CriticalCVSS 9.8No exploitEPSS 1%quantumcloud · wpbotJan 24, 2024
- CVE-2021-2450635Monitor
Slider Hero < 8.2.7 - Contributor+ SQL Injection
HighCVSS 8.8No exploitEPSS 1%quantumcloud · slider heroAug 23, 2021
- CVE-2023-2441535Monitor
WordPress AI ChatBot plugin <= 4.2.8 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%quantumcloud · chatbotFeb 23, 2023
- CVE-2023-4499335Monitor
WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)
HighCVSS 8.8No exploitEPSS 0%quantumcloud · wpbotOct 9, 2023
- CVE-2023-524133Monitor
AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file
HighCVSS 8.1No exploitEPSS 2%quantumcloud · wpbotOct 19, 2023
- CVE-2023-520432Monitor
AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
HighCVSS 7.5Proof of conceptEPSS 7%quantumcloud · wpbotOct 19, 2023
- CVE-2023-521232Monitor
AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file
HighCVSS 8.1No exploitEPSS 2%quantumcloud · wpbotOct 19, 2023
- CVE-2024-045230Monitor
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback
HighCVSS 7.7No exploitEPSS 0%quantumcloud · wpbotMay 22, 2024
- CVE-2024-045330Monitor
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback
HighCVSS 7.7No exploitEPSS 0%quantumcloud · wpbotMay 22, 2024
- CVE-2023-4874128Monitor
WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injection
HighCVSS 7.2No exploitEPSS 1%quantumcloud · wpbotDec 19, 2023
- CVE-2024-3269626Monitor
WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerability
MediumCVSS 6.5No exploitEPSS 0%quantumcloud · infographic maker – ilistApr 22, 2024
- CVE-2019-1346324Monitor
An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers
MediumCVSS 6.1No exploitEPSS 1%quantumcloud · simple link directoryMar 20, 2020
- CVE-2023-166024Monitor
ChatBot < 4.4.9 - Unauthenticated Stored XSS
MediumCVSS 6.1No exploitEPSS 0%quantumcloud · wpbotMay 8, 2023
- CVE-2023-101124Monitor
ChatBot < 4.4.5 - Stored XSS via CSRF
MediumCVSS 6.1No exploitEPSS 0%quantumcloud · wpbotMay 8, 2023
- CVE-2023-525421Monitor
AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user
MediumCVSS 5.3No exploitEPSS 1%quantumcloud · wpbotOct 19, 2023
- CVE-2024-5239521Monitor
WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerability
MediumCVSS 5.3No exploitEPSS 0%quantumcloud · floating buttons for woocommerceNov 19, 2024
- CVE-2024-581121Monitor
Simple Video Directory < 1.4.4 - Contributor+ Stored XSS
MediumCVSS 5.4No exploitEPSS 0%quantumcloud · simple video directoryJul 12, 2024
- CVE-2023-165121Monitor
ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSS
MediumCVSS 5.4No exploitEPSS 0%quantumcloud · wpbotMay 8, 2023
- CVE-2023-553421Monitor
AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions
MediumCVSS 5.4No exploitEPSS 0%quantumcloud · wpbotOct 20, 2023
- CVE-2024-045120Monitor
AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback
MediumCVSS 5.0No exploitEPSS 0%quantumcloud · wpbotMay 22, 2024