📦 Embedai

by Thesamur

🔍 What is Embedai?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0747

HIGH CVSS 8.6 Jan 30, 2025

A stored XSS vulnerability in EmbedAI allows authenticated attackers to inject malicious JavaScript into chat messages. When other users view these messages, the script executes in their browsers, pot...

CVE-2025-0744

HIGH CVSS 7.5 Jan 30, 2025

An authenticated attacker can change their subscription plan without payment by manipulating POST requests to the payment endpoint. This affects all EmbedAI installations version 2.1 and below where u...

CVE-2025-0745

HIGH CVSS 7.5 Jan 30, 2025

An Improper Access Control vulnerability in EmbedAI 2.1 and earlier allows authenticated attackers to access database backup files via a specific endpoint. This exposes sensitive database information ...

CVE-2025-0739

HIGH CVSS 8.6 Jan 30, 2025

An Improper Access Control vulnerability in EmbedAI 2.1 and earlier allows authenticated attackers to view other users' subscription information by manipulating the SUSCBRIPTION_ID parameter. This aff...

CVE-2025-0740

HIGH CVSS 8.6 Jan 30, 2025

An authenticated attacker can access other users' chat messages in EmbedAI by manipulating the CHAT_ID parameter in the load_messages endpoint. This affects all EmbedAI users running version 2.1 or ea...

CVE-2025-0746

MEDIUM CVSS 6.1 Jan 30, 2025

A reflected cross-site scripting vulnerability in EmbedAI versions 2.1 and below allows authenticated attackers to inject malicious JavaScript via crafted URLs. When users click these malicious links,...

CVE-2025-0742

MEDIUM CVSS 5.8 Jan 30, 2025

An Improper Access Control vulnerability in EmbedAI 2.1 and earlier allows authenticated attackers to access other users' files by manipulating the FILE_ID parameter in the /embedai/files/show/ endpoi...

CVE-2025-0741

MEDIUM CVSS 5.8 Jan 30, 2025

An authenticated attacker can write messages into other users' chat sessions by manipulating the 'chat_id' parameter in EmbedAI's chat functionality. This affects all users of EmbedAI version 2.1 and ...