Quantumcloud maintains a narrow product portfolio centered on WordPress plugins and web-based tools such as WPBot, Slider Hero, Simple Link Directory, Simple Video Directory, and Chatbot, which together reach a notably prominent deployment footprint across small-to-medium web properties. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the internet-facing and user-input-processing nature of plugin-based web extensions. The exposure recurs consistently through application-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and improper authorization and access control, which are characteristic of web-application middleware that handles user-supplied content and administrative functions. Defenders tracking WordPress environments should prioritize this vendor's advisories and ensure rapid patching cycles, since its products are often installed across multiple sites with varying update discipline; live exploitation activity and severity figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Quantumcloud over time
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-0747CRITICAL The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (av | Mar 21, 2022 | 9.8 | 51 | NO | YES |
CVE-2023-1650CRITICAL The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Objec | May 8, 2023 | 9.8 | 41 | NO | NO |
CVE-2022-0760CRITICAL The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX actio | Mar 21, 2022 | 9.8 | 39 | NO | YES |
CVE-2023-5204HIGH The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied p | Oct 19, 2023 | 7.5 | 32 | NO | YES |
CVE-2026-57682HIGH Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions. | Jul 2, 2026 | 7.1 | 31 | NO | NO |
CVE-2025-49901CRITICAL Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects | Oct 22, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-5533CRITICAL The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and includi | Oct 20, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-32729HIGH Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal.
This issue aff | Jun 17, 2026 | 7.5 | 27 | NO | NO |
CVE-2023-5212HIGH The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authentica | Oct 19, 2023 | 8.1 | 27 | NO | NO |
CVE-2021-24506HIGH The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using | Aug 23, 2021 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Quantumcloud.
Media articles that mention a CVE ID that affects a product developed by Quantumcloud — matched by CVE ID, not by vendor name.