Joyland.ai

6 known vulnerabilities in Joyland.ai, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-102671 CVSS 6.9 medium The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
  • CVE-2026-102670 CVSS 5.3 medium Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
  • CVE-2026-102669 CVSS 6.9 medium Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
  • CVE-2026-102668 CVSS 6.9 medium The Joyland AI app accepts any TLS certificates from any server without validation.
  • CVE-2026-102667 CVSS 9.0 critical Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted…
  • CVE-2026-102666 CVSS 6.9 medium The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST…