Joyland has 6 CVEs on record. Disclosure cadence is accelerating: 6 in the last 90 days against 0 in the 90 before. The busiest recent month was October 2026 with 6. The median CVSS is 5.3 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 6 prev 0
Worst active — by depth score
CVE-2026-102667High· 8.3Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView46CVE-2026-102666Medium· 6.5The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all us…36CVE-2026-102671Medium· 5.3The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.29CVE-2026-102669Medium· 5.3Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.29CVE-2026-102668Medium· 5.3The Joyland AI app accepts any TLS certificates from any server without validation.29
Joyland vulnerabilities
CVEs affecting Joyland, newest first. Open any entry for full detail, references, and exploit status.
6 CVEsRSS
CVE-2026-102670Medium· 4.3Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
Joyland AI app explicitly permits cleartext HTTP traffic on Android 9+ where the default is to block it.
CVE-2026-102667High· 8.3Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView
Joyland AI app allows an attacker with shared network access to inject JavaScript into content loaded in WebView. Without user-granted permissions, an attacker could access the clipboard, make arbitrary HTTP requests via the Weex 'stream…
CVE-2026-102668Medium· 5.3The Joyland AI app accepts any TLS certificates from any server without validation.
The Joyland AI app accepts any TLS certificates from any server without validation.
CVE-2026-102666Medium· 6.5The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all us…
The Joyland AI app contains hard-coded credentials for the GeTui push notification service, allowing an attacker to access the GeTui REST API and send push notifications containing arbitrary content to any user, group of users, or all us…
CVE-2026-102671Medium· 5.3The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
The Joyland AI app accepts invalid SSL certificates in the invisible advertisement WebView by default.
CVE-2026-102669Medium· 5.3Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.
Joyland AI app does not verify hostnames, allowing a malicious host to connect or intercept chat messages.