Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

QuantumCloud — Vulnerabilities & Security Advisories 70

Browse all 70 CVE security advisories affecting QuantumCloud. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QuantumCloud operates as a hybrid cloud infrastructure provider, offering scalable computing resources and data storage solutions to enterprise clients. Security audits have identified fifty-two Common Vulnerabilities and Exposures (CVEs) associated with its platform, indicating persistent weaknesses in its software development lifecycle. The majority of these vulnerabilities fall into critical categories, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from inadequate input validation and improper access control mechanisms within its web interface and API endpoints. While no widespread data breaches have been publicly confirmed, the high volume of disclosed CVEs suggests a reactive rather than proactive security posture. Recent patches have addressed several critical RCE vectors, yet the recurring nature of these flaws highlights ongoing challenges in maintaining robust defense-in-depth strategies across its distributed architecture.

CVE IDTitleCVSSSeverityPublished
CVE-2025-53200 WordPress ChatBot plugin <= 6.7.3 - Broken Access Control Vulnerability — ChatBotCWE-862 4.3 Medium2025-06-27
CVE-2025-31053 WordPress KBx Pro Ultimate plugin < 8.0.5 - Arbitrary File Deletion Vulnerability — KBx Pro UltimateCWE-22 7.7 High2025-05-23
CVE-2025-31918 WordPress Simple Business Directory Pro plugin < 15.6.9 - Privilege Escalation vulnerability — Simple Business Directory ProCWE-266 9.8 Critical2025-05-23
CVE-2025-47582 WordPress WPBot Pro Wordpress Chatbot <= 12.7.0 - PHP Object Injection Vulnerability — WPBot Pro Wordpress ChatbotCWE-502 9.8 Critical2025-05-19
CVE-2025-3812 WPBot Pro Wordpress Chatbot <= 13.6.2 - Authenticated (Subscriber+) Arbitrary File Deletion — WPBot Pro Wordpress ChatbotCWE-73 8.1 High2025-05-17
CVE-2025-32296 WordPress Simple Link Directory Pro plugin < 14.8.1 - Broken Access Control Vulnerability — Simple Link DirectoryCWE-862 5.3 Medium2025-05-16
CVE-2025-32244 WordPress SEO Help plugin <= 6.7.9 - Broken Access Control vulnerability — SEO HelpCWE-862 6.5 Medium2025-04-10
CVE-2025-32675 WordPress SEO Help plugin <= 6.7.9 - Server Side Request Forgery (SSRF) vulnerability — SEO HelpCWE-918 6.8 Medium2025-04-09
CVE-2025-26932 WordPress WPBot plugin <= 6.3.5 - Local File Inclusion vulnerability — ChatBotCWE-98 7.5 High2025-02-25
CVE-2024-12415 AI Infographic Maker <= 4.9.0 - Unauthenticated Arbitrary Shortcode Execution — AI Infographic MakerCWE-94 6.5 Medium2025-01-31
CVE-2024-12879 WPBot Pro Wordpress Chatbot <= 13.5.5 - Missing Authorization to Authenticated (Subscriber+) Simple Text Response Creation — WPBot Pro Wordpress ChatbotCWE-862 4.3 Medium2025-01-22
CVE-2024-13091 WPBot Pro Wordpress Chatbot <= 13.5.4 - Unauthenticated Arbitrary File Upload — WPBot Pro Wordpress ChatbotCWE-434 9.8 Critical2025-01-21
CVE-2025-22813 WordPress ChatBot Conversational Forms plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability — Conversational Forms for ChatBotCWE-79 6.5 Medium2025-01-09
CVE-2024-56297 WordPress Highlight plugin <= 2.0.2 - Cross Site Scripting (XSS) vulnerability — HighlightCWE-79 5.9 Medium2025-01-07
CVE-2024-56238 WordPress Floating Action Buttons plugin <= 0.9.1 - Broken Access Control vulnerability — Floating Action ButtonsCWE-862 5.3 Medium2025-01-02
CVE-2024-12417 Simple Link Directory <= 8.4.5 - Unauthenticated Arbitrary Shortcode Execution — Simple Link DirectoryCWE-94 6.5 Medium2024-12-13
CVE-2024-12156 AI Content Writer, RSS Feed to Post, Autoblogging SEO Help <= 6.1.3 - Reflected Cross-Site Scripting — QC SEO Help for llms.txt, AI Analytics, AI Content Writer, Subtitle to ArticleCWE-79 6.1 Medium2024-12-12
CVE-2024-11928 iChart – Easy Charts and Graphs <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via width Parameter — iChart – Easy Charts and GraphsCWE-79 6.4 Medium2024-12-10
CVE-2024-52395 WordPress Floating Buttons for WooCommerce plugin <= 2.8.8 - Broken Access Control vulnerability — Floating Buttons for WooCommerceCWE-862 5.3 Medium2024-11-19
CVE-2024-6669 AI ChatBot for WordPress – WPBot <= 5.5.7 - Authenticated (Administrator+) Stored Cross-Site Scripting — WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-79 5.5 Medium2024-07-17
CVE-2024-5858 Infographic Maker iList <= 4.7.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Title Update — AI Infographic MakerCWE-862 4.3 Medium2024-06-15
CVE-2024-0453 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_delete_callback — WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-284 5.0 Medium2024-05-22
CVE-2024-0452 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_upload_callback — WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-284 5.0 Medium2024-05-22
CVE-2024-0451 AI ChatBot <= 5.3.4 - Missing Authorization via openai_file_list_callback — WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-284 5.0 Medium2024-05-22
CVE-2024-34380 WordPress ChatBot Conversational Forms plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability — Conversational Forms for ChatBotCWE-79 5.9 Medium2024-05-06
CVE-2024-32696 WordPress AI Infographic Maker OpenAI plugin <= 4.6.6 - Cross Site Scripting (XSS) vulnerability — Infographic Maker – iListCWE-79 6.5 Medium2024-04-22
CVE-2024-22309 WordPress ChatBot Plugin <= 5.1.0 is vulnerable to PHP Object Injection — ChatBot with AICWE-502 8.7 High2024-01-24
CVE-2023-48741 WordPress ChatBot Plugin <= 4.7.8 is vulnerable to SQL Injection — AI ChatBotCWE-89 7.6 High2023-12-19
CVE-2023-5606 WordPress Plugin ChatBot 跨站脚本漏洞 — AI ChatBot 4.4 Medium2023-11-02
CVE-2023-5533 AI ChatBot <= 4.8.9 and 4.9.2 - Missing Authorization on AJAX actions — WPBot – AI ChatBot for Live Support, Lead Generation, AI ServicesCWE-862 5.3 Medium2023-10-20

This page lists every published CVE security advisory associated with QuantumCloud. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.