jordymeow ai engine是jordymeow个人开发者开源的一款人工智能算法引擎。 jordymeow ai engine 3.5.5之前版本存在授权问题漏洞,该漏洞源于未能验证用户是否拥有由客户端标识符引用的聊天机器人对话,导致具有订阅者访问权限的用户可以读取其他用户的私有对话并接管其对话记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12907 | RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation an | |
| CVE-2026-12978 | FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form | |
| CVE-2026-12979 | FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Impor | |
| CVE-2026-12869 | Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import | |
| CVE-2026-12525 | Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator | |
| CVE-2026-12906 | RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure | |
| CVE-2026-12585 | Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleab | |
| CVE-2026-12684 | Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr | |
| CVE-2026-11866 | LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF | |
| CVE-2026-11371 | BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection | |
| CVE-2026-12492 | Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_ | |
| CVE-2026-12395 | WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter |
No comments yet