cbcvebase.

Quantumcloud Ai Chatbot vulnerabilities

5 known vulnerabilities affecting quantumcloud/ai_chatbot.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-48741P3HIGHCVSS 7.2≥ n/a, ≤ 4.7.82023-12-19
CVE-2023-48741 [HIGH] CWE-89 CVE-2023-48741: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI ChatBot: from n/a through 4.7.8.
nvd
CVE-2023-44993P4HIGHCVSS 8.8≥ n/a, ≤ 4.7.82023-10-09
CVE-2023-44993 [HIGH] CWE-352 CVE-2023-44993: Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions. Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.
nvd
CVE-2023-24415P4HIGHCVSS 8.8≥ n/a, ≤ 4.2.82023-02-23
CVE-2023-24415 [HIGH] CWE-352 CVE-2023-24415: Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.
nvd
CVE-2023-4253P4MEDIUMCVSS 4.8≥ 4.8.6, ≤ 4.9.62023-09-04
CVE-2023-4253 [MEDIUM] CVE-2023-4253: The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, whic The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
nvd
CVE-2022-47613P4MEDIUMCVSS 4.8≥ n/a, ≤ 4.3.02023-03-29
CVE-2022-47613 [MEDIUM] CWE-79 CVE-2022-47613: Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in QuantumCloud AI ChatBot plugin <= 4.3.0 versions.
nvd
Quantumcloud Ai Chatbot vulnerabilities | cvebase