Meowapps maintains a focused portfolio of utility and media-processing applications, including AI and photo-enhancement tools, database cleaners, and file-renaming utilities that serve a consumer and small-business user base. Despite a narrow product scope, the vendor's disclosures span a meaningful volume and cluster around input-handling and data-exposure weakness classes: cross-site scripting, unrestricted file uploads, SQL injection, and sensitive-information leakage appear consistently across the product line, reflecting the challenge of securing web-facing and file-processing interfaces in consumer software. A moderate tendency toward public exploit availability characterizes this vendor's exposure, typical of application-layer vulnerabilities where tooling and proof-of-concept code propagate readily. Defenders should treat this vendor's product stack as modestly represented in vulnerability inventories but should prioritize patching where these tools are deployed in multi-user or internet-accessible environments, as input-validation and access-control weaknesses in utility software often serve as stepping stones to lateral movement or data access. Live severity, exploitation, and product-exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Meowapps over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-51409CRITICAL Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 1.9.98. | Apr 12, 2024 | 9.8 | 76 | NO | YES |
CVE-2023-44982HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Perfect Images (Manage Image Sizes, Thumbnails, Replace, Retina).This issue affects Perfect I | Dec 19, 2023 | 7.5 | 32 | NO | YES |
CVE-2025-5071HIGH The AI Engine plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on the 'Meow_MWAI_Labs_MCP::can_access_mcp' | Jun 19, 2025 | 8.8 | 26 | NO | NO |
CVE-2026-27407HIGH Editor Privilege Escalation in AI Engine <= 3.4.9 versions. | Jun 15, 2026 | 7.2 | 25 | NO | NO |
CVE-2021-24465HIGH The Meow Gallery WordPress plugin before 4.1.9 does not sanitise, validate or escape the ids attribute of its gallery shortcode (available for users as low as Contributor) before u | Oct 4, 2021 | 8.1 | 25 | NO | NO |
CVE-2025-6238HIGH The AI Engine plugin for WordPress is vulnerable to open redirect in version 2.8.4. This is due to an insecure OAuth implementation, as the 'redirect_uri' parameter is missing vali | Jul 4, 2025 | 8.0 | 23 | NO | NO |
CVE-2024-43332HIGH Missing Authorization vulnerability in Jordy Meow Photo Engine allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Engine: from n/a thr | Nov 1, 2024 | 8.8 | 23 | NO | NO |
CVE-2024-6451HIGH AI Engine < 2.4.3 is susceptible to remote-code-execution (RCE) via Log Poisoning. The AI Engine WordPress plugin before 2.5.1 fails to validate the file extension of "logs_path", | Aug 19, 2024 | 7.2 | 22 | NO | NO |
CVE-2024-10499HIGH The AI Engine WordPress plugin before 2.6.5 does not sanitize and escape a parameter from one of its RESP API endpoint before using it in a SQL statement, allowing admins to perfor | Dec 12, 2024 | 7.2 | 21 | NO | NO |
CVE-2023-51508HIGH Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Jordy Meow Database Cleaner: Clean, Optimize & Repair.This issue affects Database Cleaner: Clean, Optimi | Jan 8, 2024 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Meowapps.
Media articles that mention a CVE ID that affects a product developed by Meowapps — matched by CVE ID, not by vendor name.