Vendor
Meow Apps vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 9 vulnerabilities in Meow Apps: 1 in the last 7 days and 5 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-93623, was published on 23 September 2026. 1 technology has a page of its own.
- Last 7 days
- 1
- Last 90 days
- 5
- Critical, all time
- 0
- Exploited in the wild
- 0
About Meow Apps
Meow Apps is a developer of various WordPress plugins focused on AI, photography, and site optimization.
Meow Apps technologies
Latest Meow Apps vulnerabilities
- CVE-2026-93623: Meow Apps AI Engine IDOR vulnerabilitymediumCVSS 5.3EPSS 0.2%
- CVE-2026-15988: Meow Apps AI Engine CSRF-based auth bypass in reauth_for_authorizehighCVSS 8.8
- CVE-2026-4912: Tigroumeow Media Cleaner SSRF in get_urls_from_htmlmediumCVSS 4.1
- CVE-2026-12510: Jordy Meow AI Engine IDOR in Chatbot DiscussionsinfoCVSS 5.9
- CVE-2025-6784: tigroumeow Code Engine remote code execution via shortcodehighCVSS 8.8
- CVE-2026-27407: Meow Apps AI Engine privilege escalation in WordPress pluginhighCVSS 7.2
- CVE-2026-1291: Jordy Meow Meow Gallery unauthorized data modification in REST APImediumCVSS 4.3
- CVE-2026-8719: Jordy Meow AI Engine privilege escalation in MCP OAuth pathhighCVSS 8.8
- CVE-2026-39506: Jordy Meow AI Engine (Pro) missing authorization in WordPress pluginmediumCVSS 4.3EPSS 0.2%
Most severe Meow Apps vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-15988: Meow Apps AI Engine CSRF-based auth bypass in reauth_for_authorizehighCVSS 8.8
- CVE-2025-6784: tigroumeow Code Engine remote code execution via shortcodehighCVSS 8.8
- CVE-2026-8719: Jordy Meow AI Engine privilege escalation in MCP OAuth pathhighCVSS 8.8
- CVE-2026-27407: Meow Apps AI Engine privilege escalation in WordPress pluginhighCVSS 7.2
- CVE-2026-93623: Meow Apps AI Engine IDOR vulnerabilitymediumCVSS 5.3EPSS 0.2%
- CVE-2026-39506: Jordy Meow AI Engine (Pro) missing authorization in WordPress pluginmediumCVSS 4.3EPSS 0.2%
- CVE-2026-1291: Jordy Meow Meow Gallery unauthorized data modification in REST APImediumCVSS 4.3
- CVE-2026-4912: Tigroumeow Media Cleaner SSRF in get_urls_from_htmlmediumCVSS 4.1
- CVE-2026-12510: Jordy Meow AI Engine IDOR in Chatbot DiscussionsinfoCVSS 5.9
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 2 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 1 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/meow-apps.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Meow Apps vulnerabilities", https://junglewise.ai/threats/vendors/meow-apps, 26 September 2026.