Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

tigroumeow — Vulnerabilities & Security Advisories 21

Browse all 21 CVE security advisories affecting tigroumeow. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Tigroumeow is a security researcher focused on identifying vulnerabilities in web applications and software systems, with 14 CVEs primarily related to remote code execution and cross-site scripting flaws. Their work often targets popular open-source platforms and enterprise software, highlighting weaknesses in input validation and authentication mechanisms. While no major public incidents are directly attributed to tigroumeow, their contributions to vulnerability databases demonstrate consistent findings in privilege escalation and server-side request forgery categories. The researcher's CVE history shows a pattern of exposing flaws in widely used systems, contributing to improved security practices across affected vendors.

CVE ID Title CVSS Severity Published
CVE-2026-96561 AI Engine <= 3.8.0 - Unauthenticated Stored Cross-Site Scripting via 'model_' Parameter → PHP Error-Log Injection → Advisor Indirect Prompt Injection — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-79 7.2 High 2026-10-01
CVE-2026-89141 AI Engine <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Attachment Disclosure via 'mediaId' Parameter — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-639 6.5 Medium 2026-09-15
CVE-2026-15988 AI Engine <= 3.6.5 - Cross-Site Request Forgery to Privilege Escalation via REQUEST_URI Substring Match — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-352 8.8 High 2026-08-01
CVE-2026-4912 Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+) Server-Side Request Forgery — Media Cleaner: Clean your WordPress! CWE-918 4.1 Medium 2026-07-28
CVE-2025-6784 Code Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code Execution — Code Engine – PHP Snippets, AI Functions & Automation for WordPress CWE-77 8.8 High 2026-07-11
CVE-2026-1291 Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation — Meow Gallery CWE-639 4.3 Medium 2026-06-13
CVE-2026-8719 AI Engine 3.4.9 - Authenticated (Subscriber+) Privilege Escalation via Missing Authorization in MCP OAuth Bearer Token — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-269 8.8 High 2026-05-17
CVE-2026-1400 AI Engine <= 3.3.2 - Authenticated (Editor+) Arbitrary File Upload via 'filename' Parameter in update_media_metadata Endpoint — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-434 7.2 High 2026-01-28
CVE-2026-0746 AI Engine <= 3.3.2 - Authenticated (Subscriber+) Server-Side Request Forgery — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-918 6.4 Medium 2026-01-27
CVE-2025-8084 AI Engine <= 3.1.8 - Authenticated (Editor+) Server-Side Request Forgery — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-918 6.8 Medium 2025-11-18
CVE-2025-12844 AI Engine <= 3.1.8 - Authenticated (Subscriber+) PHP Object Injection via PHAR Deserialization — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-502 7.1 High 2025-11-13
CVE-2025-11749 AI Engine <= 3.1.3 - Unauthenticated Sensitive Information Exposure to Privilege Escalation — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-200 9.8 Critical 2025-11-05
CVE-2025-8268 Ai Engine <= 2.9.5 - Missing Authorization to Unauthenticated Uploaded Files Disclosure And Deletion — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-862 6.5 Medium 2025-09-03
CVE-2025-7847 AI Engine 2.9.3 - 2.9.4 - Authenticated (Subscriber+) Arbitrary File Upload — AI Engine CWE-434 8.8 High 2025-07-31
CVE-2025-7780 AI Engine <= 2.9.4 - Missing URL Scheme Validation to Authenticated (Subscriber+) Arbitrary File Read via simpleTranscribeAudio and get_audio Functions — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-200 6.5 Medium 2025-07-24
CVE-2025-5570 AI Engine <= 2.8.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via `mwai_chatbot` Shortcode `id` Parameter — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-79 5.4 Medium 2025-07-08
CVE-2025-6238 AI Engine 2.8.4 - Insecure OAuth Implementation — AI Engine CWE-601 8.0 High 2025-07-04
CVE-2025-5071 AI Engine 2.8.0 - 2.8.3 - Authenticated (Subscriber+) Insufficient Authorization to Privilege Escalation via MCP — AI Engine CWE-863 8.8 High 2025-06-19
CVE-2024-4386 Gallery Block (Meow Gallery) <= 5.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting — Meow Gallery CWE-79 6.4 Medium 2024-05-09
CVE-2024-0378 AI Engine <= 2.2.0 - Unauthenticated Stored Cross-Site Scripting — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-79 6.5 Medium 2024-03-02
CVE-2024-0699 AI Engine <= 2.1.4 - Authenticated(Editor+) Arbitrary File Upload via add_image_from_url — AI Engine – The Chatbot, AI Framework & MCP for WordPress CWE-434 6.6 Medium 2024-02-05

This page lists every published CVE security advisory associated with tigroumeow. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.