Vulnerabilities in quantumcloud

72 results
Vexday analysis

A QuantumCloud apresenta 34 vulnerabilidades cadastradas, com 9 classificadas como críticas (CVSS alto), mas nenhuma sob exploração ativa confirmada no KEV. A fraqueza dominante é injeção de conteúdo (CWE-79), padrão clássico em aplicações web; o ritmo de descobertas permanece significativo com 8 CVEs nos últimos 90 dias, indicando superfície de ataque em evolução contínua que demanda monitoramento constante.

CVE-2023-5204CRITICALAI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_responseEPSS 6.8%CVE-2023-5241CRITICALAI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_fileEPSS 2.1%CVE-2023-5212CRITICALAI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_fileEPSS 1.6%CVE-2026-13731HIGHWPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' ParameterEPSS 0.9%CVE-2024-13091CRITICALWPBot Pro Wordpress Chatbot <= 13.5.4 - Unauthenticated Arbitrary File UploadEPSS 0.8%CVE-2025-26932HIGHWordPress WPBot plugin <= 6.3.5 - Local File Inclusion vulnerabilityEPSS 0.8%CVE-2023-5254MEDIUMAI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_userEPSS 0.8%CVE-2025-49901CRITICALWordPress Simple Link Directory plugin < 14.8.1 - Broken Authentication vulnerabilityEPSS 0.7%CVE-2023-48741HIGHWordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL InjectionEPSS 0.7%CVE-2025-3812HIGHWPBot Pro Wordpress Chatbot <= 13.6.2 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.6%CVE-2025-60232CRITICALWordPress KBx Pro Ultimate plugin <= 8.0.5 - PHP Object Injection vulnerabilityEPSS 0.6%CVE-2025-47582CRITICALWordPress WPBot Pro Wordpress Chatbot <= 12.7.0 - PHP Object Injection VulnerabilityEPSS 0.6%CVE-2023-5533MEDIUMAI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actionsEPSS 0.5%CVE-2026-83593HIGHWPBot <= 8.7.3 - Unauthenticated Stored Cross-Site Scripting via 'conversation' ParameterEPSS 0.5%CVE-2024-22309HIGHWordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object InjectionEPSS 0.5%CVE-2025-31053HIGHWordPress KBx Pro Ultimate plugin < 8.0.5 - Arbitrary File Deletion VulnerabilityEPSS 0.5%CVE-2025-31918CRITICALWordPress Simple Business Directory Pro plugin < 15.6.9 - Privilege Escalation vulnerabilityEPSS 0.5%CVE-2026-17582MEDIUMSlider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate)EPSS 0.5%CVE-2026-57710CRITICALWordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerabilityEPSS 0.5%CVE-2024-12417MEDIUMSimple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%