Search
Search Results (29 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-4254 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.8 Medium |
| The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2023-4253 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.8 Medium |
| The AI ChatBot WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2023-1660 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 6.1 Medium |
| The AI ChatBot WordPress plugin before 4.4.9 does not have authorisation and CSRF in a function hooked to init, allowing unauthenticated users to update some settings, leading to Stored XSS due to the lack of escaping when outputting them in the admin dashboard | ||||
| CVE-2023-1011 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 6.1 Medium |
| The AI ChatBot WordPress plugin before 4.4.5 does not escape most of its settings before outputting them back in the dashboard, and does not have a proper CSRF check, allowing attackers to make a logged in admin set XSS payloads in them. | ||||
| CVE-2023-5606 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.4 Medium |
| The ChatBot for WordPress is vulnerable to Stored Cross-Site Scripting via the FAQ Builder in versions 4.8.6 through 4.9.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. NOTE: This vulnerability is a re-introduction of CVE-2023-4253. | ||||
| CVE-2023-2742 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.8 Medium |
| The AI ChatBot WordPress plugin before 4.5.5 does not sanitize and escape its settings, allowing high-privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | ||||
| CVE-2023-1650 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 9.8 Critical |
| The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Object Injection when a suitable gadget is present on the blog | ||||
| CVE-2023-44993 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.3 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <= 4.7.8 versions. | ||||
| CVE-2023-1649 | 1 Quantumcloud | 1 Wpbot | 2025-05-12 | 4.8 Medium |
| The AI ChatBot WordPress plugin before 4.5.1 does not sanitise and escape numerous of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||