Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Simple Video Directory CRITICAL 9.8
CVE-2024-6809

The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an …

Fix: 1.4.3+
Fix from $2,300 2025-05-15
Simple Video Directory MEDIUM 5.4
CVE-2024-5811

The Simple Video Directory WordPress plugin before 1.4.4 does not sanitise and escape some of its settings, which could allow contributors and higher…

Fix: 1.4.4+
Fix from $1,600 2024-07-12
Wpbot HIGH 7.7
CVE-2024-0452

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_upload_ca…

Fix: 5.3.6+
Fix from $1,950 2024-05-22
Wpbot HIGH 7.7
CVE-2024-0453

The AI ChatBot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the openai_file_delete_ca…

Fix: 5.3.6+
Fix from $1,950 2024-05-22
Wpbot MEDIUM 5.0
CVE-2024-0451

The AI ChatBot plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the openai_file_list_callback f…

Fix: 5.3.6+
Fix from $1,600 2024-05-22
Wpbot CRITICAL 9.8
CVE-2024-22309

Deserialization of Untrusted Data vulnerability in QuantumCloud ChatBot with AI.This issue affects ChatBot with AI: from n/a through 5.1.0.

Fix: 5.1.1+
Fix from $2,300 2024-01-24
Wpbot HIGH 7.2
CVE-2023-48741

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuantumCloud AI ChatBot.This issue affects AI C…

Fix: after 4.7.8
Fix from $1,950 2023-12-19
Wpbot CRITICAL 9.8
CVE-2023-5533

The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions…

Fix: after 4.8.9
Fix from $2,300 2023-10-20
Wpbot MEDIUM 5.4
CVE-2023-5534

The AI ChatBot plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.9 and 4.9.2. This is due to mis…

Fix: after 4.8.9
Fix from $1,600 2023-10-20
Wpbot MEDIUM 5.3
CVE-2023-5254

The ChatBot plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 4.8.9 via the qcld_wb_chatbot_chec…

Fix: 4.9.1+
Fix from $1,600 2023-10-19
Wpbot HIGH 8.1
CVE-2023-5212

The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This m…

Fix: 4.9.1+
Fix from $1,950 2023-10-19
Wpbot HIGH 8.1
CVE-2023-5241

The AI ChatBot for WordPress is vulnerable to Directory Traversal in versions up to, and including, 4.8.9 as well as 4.9.2 via the qcld_openai_upload…

Fix: 4.9.1+
Fix from $1,950 2023-10-19
Wpbot HIGH 7.5
CVE-2023-5204EPSS 7%

The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient …

Fix: 4.9.1+
Fix from $1,950 2023-10-19
Wpbot HIGH 8.8
CVE-2023-44993

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions.

Fix: after 4.7.8
Fix from $1,950 2023-10-09
Wpbot MEDIUM 6.1
CVE-2023-1660

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to upd…

Fix: 4.4.9+
Fix from $1,600 2023-05-08
Wpbot CRITICAL 9.8
CVE-2023-1650EPSS 34%

The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could …

Fix: 4.4.7+
Fix from $2,300 2023-05-08
Wpbot MEDIUM 6.1
CVE-2023-1011

The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a p…

Fix: 4.4.5+
Fix from $1,600 2023-05-08
Wpbot MEDIUM 5.4
CVE-2023-1651

The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in the AJAX action responsible to update the OpenAI settings, allow…

Fix: 4.4.9+
Fix from $1,600 2023-05-08
Chatbot HIGH 8.8
CVE-2023-24415

Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.2.8 versions.

Fix: 4.2.9+
Fix from $1,950 2023-02-23
Infographic Maker CRITICAL 9.8
CVE-2022-0747EPSS 15%

The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcl…

Fix: 4.3.8+
Fix from $2,300 2022-03-21
Simple Link Directory CRITICAL 9.8
CVE-2022-0760EPSS 11%

The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the…

Fix: 7.7.2+
Fix from $2,300 2022-03-21
Slider Hero HIGH 8.8
CVE-2021-24506

The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero…

Fix: 8.2.7+
Fix from $1,950 2021-08-23
Simple Link Directory MEDIUM 6.1
CVE-2019-13463

An XSS vulnerability in qcopd-shortcode-generator.php in the Simple Link Directory plugin before 7.3.5 for WordPress allows remote attackers to injec…

Fix: 7.3.5+
Fix from $1,600 2020-03-20