Joyland AI 应用程序接受来自任何服务器的任意 TLS 证书,且未进行验证。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Joyland | Joyland.ai | * |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Joyland | Joyland.ai | * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-102667 | 8.3 HIGH | Joyland AI WebView command injection |
| CVE-2026-102666 | 6.5 MEDIUM | Joyland AI hard-coded credentials for push notifications |
| CVE-2026-102671 | 5.3 MEDIUM | Joyland AI WebView accepts invalid SSL certificates |
| CVE-2026-102669 | 5.3 MEDIUM | Joyland AI hostname checking disabled |
| CVE-2026-102670 | 4.3 MEDIUM | Joyland AI enables HTTP |
No comments yet