Thesamur maintains a focused product line centered on EmbedAI, an embedded artificial-intelligence platform whose vulnerability profile reflects the access-control and input-handling demands of web-facing AI integration layers. The recurring weakness classes—improper access control and cross-site scripting—are characteristic of authentication and client-side rendering surfaces in such systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thesamur over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-0745MEDIUM An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain the backups of the database by reque | Jan 30, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-0740MEDIUM An Improper Access Control vulnerability has been found in EmbedAI
2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other u | Jan 30, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-0739MEDIUM An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others u | Jan 30, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-0747MEDIUM A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that | Jan 30, 2025 | 5.4 | 18 | NO | NO |
CVE-2025-0742MEDIUM An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by chan | Jan 30, 2025 | 6.5 | 18 | NO | NO |
CVE-2025-0744MEDIUM an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by | Jan 30, 2025 | 6.5 | 17 | NO | NO |
CVE-2025-0746MEDIUM A Reflected Cross-Site Scripting vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to craft a malicious URL leveraging the" | Jan 30, 2025 | 5.4 | 16 | NO | NO |
CVE-2025-0743MEDIUM An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show | Jan 30, 2025 | 4.3 | 15 | NO | NO |
CVE-2025-0741MEDIUM An Improper Access Control vulnerability has been found in EmbedAI
2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by c | Jan 30, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thesamur.
Media articles that mention a CVE ID that affects a product developed by Thesamur — matched by CVE ID, not by vendor name.