Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Chatbot — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Chatbot, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of security weaknesses and vulnerabilities associated with the Chatbot product category, covering various vendor implementations and general AI assistant software. It serves as a centralized resource for tracking security issues that impact conversational AI platforms, including large language model interfaces and customer service automation tools. The vulnerability database on this page collects reports spanning multiple years, capturing historical data and recent findings to provide a complete picture of the security landscape for chatbot technologies. This includes issues related to input validation, session management, data leakage, prompt injection attacks, and unauthorized access controls. The collection focuses on both critical infrastructure-level flaws and application-specific bugs that may expose sensitive user data or allow malicious manipulation of the AI system. Visitors can use this resource to track a vendor's advisories as they release patches for identified security risks. Users can also gain a deeper understanding of a specific weakness class by observing how it manifests across different chatbot implementations and environments. Additionally, the page allows for detailed lookup of a product's vulnerability history, enabling security teams to assess the stability and maturity of a particular chatbot solution over time. This information supports risk assessment, compliance reporting, and informed decision-making when selecting or updating conversational AI systems. By consolidating these data points, the page aims to improve transparency and security awareness within the developer and enterprise communities.

Vendor: CBOT

CVE ID Title CVSS Severity Published
CVE-2026-57363 WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-13
CVE-2026-57362 WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-07-02
CVE-2026-40788 WordPress ChatBot plugin <= 7.9.7 - Broken Access Control vulnerability CWE-862 7.1 High 2026-06-15
CVE-2026-32499 WordPress ChatBot plugin <= 7.7.9 - SQL Injection vulnerability CWE-89 9.3 Critical 2026-03-25
CVE-2025-64277 WordPress ChatBot plugin <= 7.3.9 - Broken Access Control vulnerability CWE-862 5.3 Medium 2025-11-13
CVE-2025-62952 WordPress ChatBot plugin <= 7.7.3 - Broken Access Control vulnerability CWE-862 4.3 Medium 2025-10-27
CVE-2025-11952 Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot CWE-79 5.4AI Medium AI 2025-10-22
CVE-2025-10869 Stored Cross-Site Scripting (XSS) in Oct8ne Chatbot CWE-79 5.4AI Medium AI 2025-10-15
CVE-2025-53200 WordPress ChatBot plugin <= 6.7.3 - Broken Access Control Vulnerability CWE-862 4.3 Medium 2025-06-27
CVE-2025-26932 WordPress WPBot plugin <= 6.3.5 - Local File Inclusion vulnerability CWE-98 7.5 High 2025-02-25
CVE-2023-2887 User Authentication Bypass in CBOT's Chatbot CWE-290 9.8 Critical 2023-05-25
CVE-2023-2886 Cross-Site WebSocket Hijacking in CBOT's Chatbot CWE-1385 4.3 Medium 2023-05-25
CVE-2023-2885 Channel Accessible by Non-Endpoint in CBOT's Chatbot CWE-924 8.1 High 2023-05-25
CVE-2023-2884 Insecure Randomness in CBOT's Chatbot CWE-338 9.8 Critical 2023-05-25
CVE-2023-2883 IDOR in CBOT's Chatbot CWE-639 8.8 High 2023-05-25
CVE-2023-2882 Privilege Escalation in CBOT's Chatbot CWE-1270 9.8 Critical 2023-05-25

All 16 known CVE vulnerabilities affecting Chatbot with full Chinese analysis, references, and POCs where available.