Ai3's vulnerability footprint centers on its QBiBot product, a web-based conversational application with recurring exposure across input-handling, authentication, and file-upload mechanisms. The durable signal reflects typical web-application weaknesses: cross-site scripting in page generation, missing authentication controls on critical functions, and unrestricted file uploads that enable arbitrary file handling.
The number and severity of CVEs published that impact products developed by Ai3 over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-3777CRITICAL The password reset feature of Ai3 QbiBot lacks proper access control, allowing unauthenticated remote attackers to reset any user's password. | Apr 15, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-3778HIGH The file upload functionality of Ai3 QbiBot does not properly restrict types of uploaded files, allowing remote attackers with administrator privilege to upload files with dangerou | Apr 15, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-7204MEDIUM Ai3 QbiBot does not properly filter user input, allowing unauthenticated remote attackers to insert JavaScript code into the chat box. Once the recipient views the message, they wi | Aug 2, 2024 | 6.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ai3.
Media articles that mention a CVE ID that affects a product developed by Ai3 — matched by CVE ID, not by vendor name.