Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

QuantumCloud — Vulnerabilities & Security Advisories 71

Browse all 71 CVE security advisories affecting QuantumCloud. AI-powered Chinese analysis, POCs, and references for each vulnerability.

QuantumCloud operates as a hybrid cloud infrastructure provider, offering scalable computing resources and data storage solutions to enterprise clients. Security audits have identified fifty-two Common Vulnerabilities and Exposures (CVEs) associated with its platform, indicating persistent weaknesses in its software development lifecycle. The majority of these vulnerabilities fall into critical categories, including remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws. These issues often stem from inadequate input validation and improper access control mechanisms within its web interface and API endpoints. While no widespread data breaches have been publicly confirmed, the high volume of disclosed CVEs suggests a reactive rather than proactive security posture. Recent patches have addressed several critical RCE vectors, yet the recurring nature of these flaws highlights ongoing challenges in maintaining robust defense-in-depth strategies across its distributed architecture.

CVE ID Title CVSS Severity Published
CVE-2026-17582 Slider Hero with Video Background, Animation <= 9.1.7 - Authenticated (Administrator+) SQL Injection via 'description' Slide Field (Second-Order via Duplicate) — Slider Hero with Video Background, Animation CWE-89 4.9 Medium 2026-08-16
CVE-2026-16773 WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services CWE-200 5.3 Medium 2026-07-28
CVE-2026-16774 WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services CWE-862 5.3 Medium 2026-07-28
CVE-2026-61953 WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Forgery (SSRF) vulnerability — Simple Link Directory Pro CWE-918 7.2 High 2026-07-27
CVE-2026-61981 WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request Forgery (CSRF) vulnerability — Simple Link Directory Pro CWE-352 5.4 Medium 2026-07-23
CVE-2026-15610 WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services CWE-862 4.3 Medium 2026-07-16
CVE-2026-15106 WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services CWE-862 5.3 Medium 2026-07-16
CVE-2026-57707 WordPress Simple Business Directory Pro plugin <= 15.9.4 - SQL Injection vulnerability — Simple Business Directory Pro CWE-89 9.3 Critical 2026-07-13
CVE-2026-57710 WordPress WoowBot Pro Max plugin <= 14.1.7 - Arbitrary File Upload vulnerability — WoowBot Pro Max CWE-434 9.9 Critical 2026-07-13
CVE-2026-57363 WordPress ChatBot plugin <= 8.3.7 - Cross Site Scripting (XSS) vulnerability — ChatBot CWE-79 7.1 High 2026-07-13
CVE-2026-57414 WordPress ChatBot for eCommerce – WoowBot plugin <= 4.6.1 - Cross Site Scripting (XSS) vulnerability — ChatBot for eCommerce &#8211; WoowBot CWE-79 6.5 Medium 2026-07-13
CVE-2026-57682 WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS) vulnerability — Simple Link Directory CWE-79 7.1 High 2026-07-02
CVE-2026-57362 WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability — ChatBot CWE-79 7.1 High 2026-07-02
CVE-2026-13731 WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter — WPBot – AI ChatBot for Live Support, Lead Generation, AI Services CWE-79 7.2 High 2026-07-01
CVE-2024-32729 WordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Download vulnerability — Conversational Forms for ChatBot CWE-22 7.5 High 2026-06-17
CVE-2025-60223 WordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Deletion vulnerability — WPBot Pro Wordpress Chatbot CWE-22 7.7 High 2026-06-17
CVE-2026-40788 WordPress ChatBot plugin <= 7.9.7 - Broken Access Control vulnerability — ChatBot CWE-862 7.1 High 2026-06-15
CVE-2026-53742 Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes — Simple Link Directory CWE-79 5.4 Medium 2026-06-10
CVE-2026-53741 Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option — Simple Link Directory CWE-79 5.4 Medium 2026-06-10
CVE-2026-7209 Simple Link Directory <= 8.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes — Simple Link Directory CWE-79 6.4 Medium 2026-05-02
CVE-2026-32499 WordPress ChatBot plugin <= 7.7.9 - SQL Injection vulnerability — ChatBot CWE-89 9.3 Critical 2026-03-25
CVE-2025-67576 WordPress Simple Link Directory plugin <= 8.8.3 - Broken Access Control vulnerability — Simple Link Directory CWE-862 5.3 Medium 2025-12-09
CVE-2025-67465 WordPress Simple Link Directory plugin <= 8.8.3 - Cross Site Request Forgery (CSRF) vulnerability — Simple Link Directory CWE-352 4.3 Medium 2025-12-09
CVE-2025-64277 WordPress ChatBot plugin <= 7.3.9 - Broken Access Control vulnerability — ChatBot CWE-862 5.3 Medium 2025-11-13
CVE-2025-62952 WordPress ChatBot plugin <= 7.7.3 - Broken Access Control vulnerability — ChatBot CWE-862 4.3 Medium 2025-10-27
CVE-2025-60232 WordPress KBx Pro Ultimate plugin <= 8.0.5 - PHP Object Injection vulnerability — KBx Pro Ultimate CWE-502 9.8 Critical 2025-10-22
CVE-2025-49901 WordPress Simple Link Directory plugin < 14.8.1 - Broken Authentication vulnerability — Simple Link Directory CWE-288 9.8 Critical 2025-10-22
CVE-2025-48162 WordPress Simple Business Directory Pro <= 15.5.1 - Cross Site Scripting (XSS) Vulnerability — Simple Business Directory Pro CWE-79 7.1 High 2025-08-20
CVE-2025-48297 WordPress Simple Link Directory < 14.8.1 - Cross Site Scripting (XSS) Vulnerability — Simple Link Directory CWE-79 7.1 High 2025-08-20
CVE-2025-53580 WordPress Simple Business Directory Pro Plugin < 15.6.9 - Privilege Escalation Vulnerability — Simple Business Directory Pro CWE-266 9.8 Critical 2025-08-20

This page lists every published CVE security advisory associated with QuantumCloud. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.