NA - CVE-2025-0740 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing...
NA - CVE-2025-0741 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the...
NA - CVE-2025-0742 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by changing the...
NA - CVE-2025-0743 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/" to obtain...
NA - CVE-2025-0744 - an Improper Access Control vulnerability has...
an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST...
NA - CVE-2025-0745 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by requesting the...
NA - CVE-2025-0746 - A Reflected Cross-Site Scripting vulnerability...
A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging...
NA - CVE-2025-0747 - A Stored Cross-Site Scripting vulnerability has...
A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that will be executed...
Medium - CVE-2024-13380 - The Alex Reservations: Smart Restaurant Booking...
The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rr_form' shortcode in all versions up to, and...