SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-57414

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The QuantumCloud ChatBot for eCommerce, specifically versions up to and including 4.6.1, is vulnerable to a stored cross-site scripting (XSS) attack due to improper input neutralization during web page generation. This vulnerability could allow an attacker to inject malicious scripts that execute in the context of a user's browser, potentially compromising user data and session integrity. E-commerce platforms utilizing this chatbot should prioritize remediation to safeguard against potential exploitation.

CVE
CVE-2026-57414
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud ChatBot for eCommerce &#8211; WoowBot woowbot-woocommerce-chatbot allows Stored XSS.This issue affects ChatBot for eCommerce &#8211; WoowBot: from n/a through <= 4.6.1.