Skip to content
Noroxi

quantumcloud records

41 published records for vendor quantumcloud.

All records

41 records
  • ChatBot < 4.4.7 - Unauthenticated PHP Object Injection

    CriticalCVSS 9.8No exploitEPSS 34%

    quantumcloud · wpbotMay 8, 2023

  • Infographic Maker - iList < 4.3.8 - Unauthenticated SQL Injection

    CriticalCVSS 9.8Proof of conceptEPSS 15%

    quantumcloud · infographic makerMar 21, 2022

  • Simple Link Directory < 7.7.2 - Unauthenticated SQL injection

    CriticalCVSS 9.8Proof of conceptEPSS 11%

    quantumcloud · simple link directoryMar 21, 2022

  • CVE-2024-6809
    39Monitor

    Simple Video Directory < 1.4.3 - Unauthenticated SQLi

    CriticalCVSS 9.8No exploitEPSS 1%

    quantumcloud · simple video directoryMay 15, 2025

  • CVE-2023-5533
    39Monitor

    AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions

    CriticalCVSS 9.8No exploitEPSS 1%

    quantumcloud · wpbotOct 20, 2023

  • WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection

    CriticalCVSS 9.8No exploitEPSS 1%

    quantumcloud · wpbotJan 24, 2024

  • Slider Hero < 8.2.7 - Contributor+ SQL Injection

    HighCVSS 8.8No exploitEPSS 1%

    quantumcloud · slider heroAug 23, 2021

  • WordPress AI ChatBot plugin <= 4.2.8 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    quantumcloud · chatbotFeb 23, 2023

  • WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF)

    HighCVSS 8.8No exploitEPSS 0%

    quantumcloud · wpbotOct 9, 2023

  • CVE-2023-5241
    33Monitor

    AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file

    HighCVSS 8.1No exploitEPSS 2%

    quantumcloud · wpbotOct 19, 2023

  • CVE-2023-5204
    32Monitor

    AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response

    HighCVSS 7.5Proof of conceptEPSS 7%

    quantumcloud · wpbotOct 19, 2023

  • CVE-2023-5212
    32Monitor

    AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file

    HighCVSS 8.1No exploitEPSS 2%

    quantumcloud · wpbotOct 19, 2023

  • CVE-2024-0452
    30Monitor

    AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback

    HighCVSS 7.7No exploitEPSS 0%

    quantumcloud · wpbotMay 22, 2024

  • CVE-2024-0453
    30Monitor

    AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback

    HighCVSS 7.7No exploitEPSS 0%

    quantumcloud · wpbotMay 22, 2024

  • WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injection

    HighCVSS 7.2No exploitEPSS 1%

    quantumcloud · wpbotDec 19, 2023

  • WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    quantumcloud · infographic maker – ilistApr 22, 2024

  • An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers

    MediumCVSS 6.1No exploitEPSS 1%

    quantumcloud · simple link directoryMar 20, 2020

  • CVE-2023-1660
    24Monitor

    ChatBot < 4.4.9 - Unauthenticated Stored XSS

    MediumCVSS 6.1No exploitEPSS 0%

    quantumcloud · wpbotMay 8, 2023

  • CVE-2023-1011
    24Monitor

    ChatBot < 4.4.5 - Stored XSS via CSRF

    MediumCVSS 6.1No exploitEPSS 0%

    quantumcloud · wpbotMay 8, 2023

  • CVE-2023-5254
    21Monitor

    AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user

    MediumCVSS 5.3No exploitEPSS 1%

    quantumcloud · wpbotOct 19, 2023

  • WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerability

    MediumCVSS 5.3No exploitEPSS 0%

    quantumcloud · floating buttons for woocommerceNov 19, 2024

  • CVE-2024-5811
    21Monitor

    Simple Video Directory < 1.4.4 - Contributor+ Stored XSS

    MediumCVSS 5.4No exploitEPSS 0%

    quantumcloud · simple video directoryJul 12, 2024

  • CVE-2023-1651
    21Monitor

    ChatBot < 4.4.9 - Subscriber+ OpenAI Settings Update to Stored XSS

    MediumCVSS 5.4No exploitEPSS 0%

    quantumcloud · wpbotMay 8, 2023

  • CVE-2023-5534
    21Monitor

    AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions

    MediumCVSS 5.4No exploitEPSS 0%

    quantumcloud · wpbotOct 20, 2023

  • CVE-2024-0451
    20Monitor

    AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback

    MediumCVSS 5.0No exploitEPSS 0%

    quantumcloud · wpbotMay 22, 2024