CVE-2026-53742: Quantumcloud Simple Link Directory

Medium severity, CVSS 5.4. EPSS: 0.2% chance of exploitation in the next 30 days.

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attribute that injects an event handler executing in a viewer's browser.

Affected products

  • Quantumcloud Simple Link Directory: up to and including 9.0.4

Published 2026-06-10. Last modified 2026-07-23.