Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Quantumcloud

First CVE: Mar 20, 2020Active for: 6 yearsTotal CVEs: 54
36.1
VTI Score
Medium

Quantumcloud maintains a narrow product portfolio centered on WordPress plugins and web-based tools such as WPBot, Slider Hero, Simple Link Directory, Simple Video Directory, and Chatbot, which together reach a notably prominent deployment footprint across small-to-medium web properties. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the internet-facing and user-input-processing nature of plugin-based web extensions. The exposure recurs consistently through application-layer weakness classes including cross-site scripting, SQL injection, cross-site request forgery, and improper authorization and access control, which are characteristic of web-application middleware that handles user-supplied content and administrative functions. Defenders tracking WordPress environments should prioritize this vendor's advisories and ensure rapid patching cycles, since its products are often installed across multiple sites with varying update discipline; live exploitation activity and severity figures are shown alongside this summary.

FAUCET AI Generated
54
Total CVEs
More Total CVEs than 99% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Quantumcloud over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2020
6 years ago
Most Recent CVE
Jul 2, 2026
22 days ago

Products(9 total)

Top CVEs

Signals from CVEs in this vendor scope (54 CVEs).

54 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-0747CRITICAL
The Infographic Maker WordPress plugin before 4.3.8 does not validate and escape the post_id parameter before using it in a SQL statement via the qcld_upvote_action AJAX action (av
Mar 21, 20229.851NOYES
CVE-2023-1650CRITICAL
The AI ChatBot WordPress plugin before 4.4.7 unserializes user input from cookies via an AJAX action available to unauthenticated users, which could allow them to perform PHP Objec
May 8, 20239.841NONO
CVE-2022-0760CRITICAL
The Simple Link Directory WordPress plugin before 7.7.2 does not validate and escape the post_id parameter before using it in a SQL statement via the qcopd_upvote_action AJAX actio
Mar 21, 20229.839NOYES
CVE-2023-5204HIGH
The ChatBot plugin for WordPress is vulnerable to SQL Injection via the $strid parameter in versions up to, and including, 4.8.9 due to insufficient escaping on the user supplied p
Oct 19, 20237.532NOYES
CVE-2026-57682HIGH
Unauthenticated Cross Site Scripting (XSS) in Simple Link Directory <= 15.0.5 versions.
Jul 2, 20267.131NONO
CVE-2025-49901CRITICAL
Authentication Bypass Using an Alternate Path or Channel vulnerability in quantumcloud Simple Link Directory qc-simple-link-directory allows Authentication Abuse.This issue affects
Oct 22, 20259.829NONO
CVE-2023-5533CRITICAL
The AI ChatBot plugin for WordPress is vulnerable to unauthorized use of AJAX actions due to missing capability checks on the corresponding functions in versions up to, and includi
Oct 20, 20239.829NONO
CVE-2024-32729HIGH
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Path Traversal. This issue aff
Jun 17, 20267.527NONO
CVE-2023-5212HIGH
The AI ChatBot plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 4.8.9 as well as version 4.9.2. This makes it possible for authentica
Oct 19, 20238.127NONO
CVE-2021-24506HIGH
The Slider Hero with Animation, Video Background & Intro Maker WordPress plugin before 8.2.7 does not sanitise or escape the id attribute of its hero-button shortcode before using
Aug 23, 20218.827NONO
View all 54 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products54 CVEs
59%
26%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network54 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None23 (42.6%)
Unknown0 (0.0%)
Required31 (57.4%)
Privileges Required
Low14 (25.9%)
High16 (29.6%)
None24 (44.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (54 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
5.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Quantumcloud.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Quantumcloud — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Quantumcloud's Products

View all 5 CNAs →

Top CWEs