Quantumcloud Chatbot vulnerabilities

6 known vulnerabilities affecting quantumcloud/chatbot.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1UNKNOWN2

Vulnerabilities

Page 1 of 1
CVE-2026-32499CRITICALCVSS 9.3≥ n/a, ≤ <= 7.7.92026-03-25
CVE-2026-32499 [CRITICAL] CWE-89 CVE-2026-32499: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability i Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud ChatBot chatbot allows Blind SQL Injection.This issue affects ChatBot: from n/a through <= 7.7.9.
cvelistv5nvd
CVE-2025-64277MEDIUMCVSS 5.3≤ 7.3.92025-11-13
CVE-2025-64277 [MEDIUM] CWE-862 CVE-2025-64277: Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Co Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.
cvelistv5nvd
CVE-2025-62952HIGHCVSS 8.8≤ 7.7.32025-10-27
CVE-2025-62952 [HIGH] CWE-862 CVE-2025-62952: Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Co Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.7.3.
cvelistv5nvd
CVE-2025-53200UNKNOWN≤ 6.7.32025-06-27
CVE-2025-53200 CWE-862 CVE-2025-53200: Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Co Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 6.7.3.
cvelistv5nvd
CVE-2025-26932UNKNOWN≤ 6.3.52025-02-25
CVE-2025-26932 CWE-98 CVE-2025-26932: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in QuantumCloud ChatBot chatbot allows PHP Local File Inclusion.This issue affects ChatBot: from n/a through <= 6.3.5.
cvelistv5nvd
CVE-2023-24415HIGHCVSS 8.8fixed in 4.2.92023-02-23
CVE-2023-24415 [HIGH] CWE-352 CVE-2023-24415: Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions. Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.
nvd