Vulnerability index

Browse CVEs

20 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ai Engine MEDIUM 5.4
CVE-2025-5570

The AI Engine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the mwai_chatbot shortcode 'id' parameter in all versions up to, …

Fix: 2.8.5+
Fix from $1,600 2025-07-08
Ai Engine HIGH 8.0
CVE-2025-6238

The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect…

Patch available
Fix from $1,950 2025-07-04
Ai Engine HIGH 8.8
CVE-2025-5071

The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow…

Fix: 2.8.4+
Fix from $1,950 2025-06-19
Ai Engine HIGH 7.2
CVE-2024-10499

The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL state…

Fix: 2.6.5+
Fix from $1,950 2024-12-12
Photo Engine HIGH 8.8
CVE-2024-43332

Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue aff…

Fix: 6.4.1+
Fix from $1,950 2024-11-01
Ai Engine HIGH 7.2
CVE-2024-6451

AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the …

Fix: 2.4.3+
Fix from $1,950 2024-08-19
Ai Engine HIGH 7.1
CVE-2024-38791

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI En…

Fix: 2.4.8+
Fix from $1,950 2024-08-01
Ai Engine HIGH 7.2
CVE-2024-34440

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:…

Fix: 2.2.70+
Fix from $1,950 2024-05-14
Ai Engine CRITICAL 9.8
CVE-2023-51409EPSS 63%

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:…

Fix: 1.9.99+
Fix from $2,300 2024-04-12
Ai Engine HIGH 7.2
CVE-2024-29100

Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot:…

Fix: 2.1.5+
Fix from $1,950 2024-03-28
Ai Engine MEDIUM 6.8
CVE-2024-29090

Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a thr…

Fix: 2.1.5+
Fix from $1,600 2024-03-28
Ai Engine HIGH 7.2
CVE-2024-0699

The AI Engine: Chatbots, Generators, Assistants, GPT 4 and more! plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ…

Fix: after 2.1.4
Fix from $1,950 2024-02-05
Database Cleaner HIGH 7.5
CVE-2023-51508

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects …

Fix: after 0.9.8
Fix from $1,950 2024-01-08
Photo Engine MEDIUM 5.4
CVE-2023-38513

Authorization Bypass Through User-Controlled Key vulnerability in Jordy Meow Photo Engine (Media Organizer & Lightroom).This issue affects Photo Engi…

Fix: 6.2.6+
Fix from $1,600 2023-12-20
Media File Renamer Auto \& Manual Rename HIGH 7.5
CVE-2023-44991

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Media File Renamer: Rename Files (Manual, Auto & AI).This issu…

Fix: after 5.6.9
Fix from $1,950 2023-12-19
Perfect Images HIGH 7.5
CVE-2023-44982

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retin…

Fix: after 6.4.5
Fix from $1,950 2023-12-19
Meow Gallery HIGH 8.1
CVE-2021-24465

The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users …

Fix: 4.1.9+
Fix from $1,950 2021-10-04
Media Usage MEDIUM 6.1
CVE-2021-34652

The Media Usage WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the id parameter in the ~/mmu_admin.php file which allows attack…

Fix: after 0.0.4
Fix from $1,600 2021-08-16
Wp Retina 2x MEDIUM 6.1
CVE-2018-20983

The wp-retina-2x plugin before 5.2.3 for WordPress has XSS.

Fix: 5.2.3+
Fix from $1,600 2019-08-22
Wp Retina 2x MEDIUM 6.1
CVE-2018-0511

Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified v…

Fix: 5.2.2+
Fix from $1,600 2018-02-01