| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2023-5534 | AI ChatBot <= 4.8.9 and 4.9.2 - Cross-Site Request Forgery on AJAX actions | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | Medium | 4.3 | 2023-10-20 07:29:23 | Deep Dive |
| CVE-2023-5212 | AI ChatBot <= 4.8.9 and 4.9.2- Authenticated (Subscriber+) Arbitrary File Deletion via qcld_openai_delete_training_file | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | Critical | 9.6 | 2023-10-19 05:34:12 | Deep Dive |
| CVE-2023-5254 | AI ChatBot <= 4.8.9 - Unauthenticated Sensitive Information Exposure via qcld_wb_chatbot_check_user | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | Medium | 5.3 | 2023-10-19 05:34:12 | Deep Dive |
| CVE-2023-5204 | AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | Critical | 9.8 | 2023-10-19 05:34:11 | Deep Dive |
| CVE-2023-5241 | AI ChatBot <= 4.8.9 and 4.9.2 - Authenticated (Subscriber+) Directory Traversal to Arbitrary File Write via qcld_openai_upload_pagetraining_file | quantumcloud | WPBot – AI ChatBot for Live Support, Lead Generation, AI Services | Critical | 9.6 | 2023-10-19 05:34:11 | Deep Dive |
| CVE-2023-44993 | WordPress ChatBot Plugin <= 4.7.8 is vulnerable to Cross Site Request Forgery (CSRF) | QuantumCloud | AI ChatBot | Medium | 4.3 | 2023-10-09 10:11:27 | Deep Dive |
| CVE-2023-4253 | Chatbot < 4.7.8 - Admin+ Stored XSS in FAQ Builder | Unknown | AI ChatBot | 中危 | - | 2023-09-04 11:26:58 | Deep Dive |
| CVE-2023-4254 | Chatbot < 4.7.8 - Admin+ Stored XSS in Language Settings | Unknown | AI ChatBot | 中危 | - | 2023-09-04 11:26:57 | Deep Dive |
| CVE-2023-3175 | AI ChatBot < 4.6.1 - Admin+ Stored Cross-Site Scripting | Unknown | AI ChatBot | 中危 | - | 2023-07-10 12:40:53 | Deep Dive |
| CVE-2023-2580 | AI-Engine < 1.6.83 - Admin+ Stored XSS | Unknown | AI Engine: ChatGPT Chatbot, Content Generator, GPT 3 & 4, Ultra-Customizable | 中危 | - | 2023-06-27 13:17:08 | Deep Dive |
| CVE-2023-2742 | AI ChatBot < 4.5.5 - Admin+ Stored Cross-Site Scripting | Unknown | AI ChatBot | 中危 | - | 2023-06-19 10:52:44 | Deep Dive |
| CVE-2023-2811 | AI ChatBot < 4.5.6 - Admin+ Stored Cross-Site Scripting | Unknown | AI ChatBot | 中危 | - | 2023-06-19 10:52:41 | Deep Dive |
| CVE-2023-2887 | User Authentication Bypass in CBOT's Chatbot | CBOT | Chatbot | Critical | 9.8 | 2023-05-25 08:33:34 | Deep Dive |
| CVE-2023-2886 | Cross-Site WebSocket Hijacking in CBOT's Chatbot | CBOT | Chatbot | Medium | 4.3 | 2023-05-25 08:31:24 | Deep Dive |
| CVE-2023-2885 | Channel Accessible by Non-Endpoint in CBOT's Chatbot | CBOT | Chatbot | High | 8.1 | 2023-05-25 08:28:56 | Deep Dive |
| CVE-2023-2884 | Insecure Randomness in CBOT's Chatbot | CBOT | Chatbot | Critical | 9.8 | 2023-05-25 08:26:40 | Deep Dive |
| CVE-2023-2883 | IDOR in CBOT's Chatbot | CBOT | Chatbot | High | 8.8 | 2023-05-25 08:20:44 | Deep Dive |
| CVE-2023-2882 | Privilege Escalation in CBOT's Chatbot | CBOT | Chatbot | Critical | 9.8 | 2023-05-25 08:18:24 | Deep Dive |
| CVE-2023-1649 | ChatBot < 4.5.1 - Admin+ Stored XSS | Unknown | AI ChatBot | 中危 | - | 2023-05-08 13:58:15 | Deep Dive |
| CVE-2023-1650 | ChatBot < 4.4.7 - Unauthenticated PHP Object Injection | Unknown | AI ChatBot | 超危 | - | 2023-05-08 13:58:13 | Deep Dive |