Vulnerabilities > Meowapps > AI Engine > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-09-13 CVE-2024-6723 SQL Injection vulnerability in Meowapps AI Engine
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
network
low complexity
meowapps CWE-89
4.7
2023-06-27 CVE-2023-2580 Unspecified vulnerability in Meowapps AI Engine
The AI Engine WordPress plugin before 1.6.83 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
network
low complexity
meowapps
4.8