Vulnerability index

Browse CVEs

61 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lollms MEDIUM 5.4
CVE-2026-12228

A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint …

Fix: after 2.1.0
Fix from $1,600 2026-07-18
Lollms MEDIUM 6.1
CVE-2026-1116

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to versi…

Fix: after 2.1.0
Fix from $1,600 2026-04-12
Lollms CRITICAL 9.6
CVE-2026-1115

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.…

Fix: after 2.1.0
Fix from $2,300 2026-04-10
Lollms CRITICAL 9.8
CVE-2026-1114

In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key f…

Patch available
Fix from $2,300 2026-04-07
Lollms HIGH 8.3
CVE-2026-0562

A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging…

Fix: after 2.1.0
Fix from $1,950 2026-03-29
Lollms HIGH 7.5
CVE-2026-0560

A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content`…

Fix: after 2.1.0
Fix from $1,950 2026-03-29
Lollms CRITICAL 9.8
CVE-2026-0558

A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/fil…

Fix: after 2.1.0
Fix from $2,300 2026-03-29
Lollms Web Ui CRITICAL 9.1
CVE-2026-33340EPSS 22%

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner…

No fix yet
Fix from $2,300 2026-03-24
Lollms Web Ui HIGH 7.5
CVE-2025-1451

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or …

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui HIGH 8.8
CVE-2024-9920

In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangero…

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui HIGH 8.4
CVE-2024-9919

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. T…

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui CRITICAL 9.8
CVE-2024-8898

A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab…

Patch available
Fix from $2,300 2025-03-20
Lollms Web Ui CRITICAL 9.1
CVE-2024-8581

A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the syst…

Patch available
Fix from $2,300 2025-03-20
Lollms Web Ui MEDIUM 6.5
CVE-2024-8736

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability…

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui MEDIUM 5.4
CVE-2024-6986

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper…

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui HIGH 7.5
CVE-2024-12766

parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attack…

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui MEDIUM 6.7
CVE-2024-10019

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The …

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui MEDIUM 5.3
CVE-2024-10047

parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on …

No fix yet
Fix from $1,600 2025-03-20
Lollms Webui HIGH 7.3
CVE-2024-5125

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of …

Patch available
Fix from $1,950 2024-11-14
Lollms Web Ui HIGH 7.1
CVE-2024-6674

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, …

Fix: 10+
Fix from $1,950 2024-10-29
Lollms Web Ui MEDIUM 6.5
CVE-2024-6673

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-web…

Fix: 10+
Fix from $1,600 2024-10-29
Lord Of Large Language Models CRITICAL 9.0
CVE-2024-6581

A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomp…

Patch available
Fix from $2,300 2024-10-29
Lollms Web Ui HIGH 7.1
CVE-2024-6959

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends…

No fix yet
Fix from $1,950 2024-10-13
Lollms Web Ui HIGH 7.5
CVE-2024-6394

A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation i…

No fix yet
Fix from $1,950 2024-09-30
Lollms Web Ui HIGH 8.8
CVE-2024-6040

In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities.…

No fix yet
Fix from $1,950 2024-08-01
Lollms Web Ui HIGH 8.4
CVE-2024-4897

parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_…

Fix: 9.8+
Fix from $1,950 2024-07-02
Lollms Web Ui HIGH 7.5
CVE-2024-6250

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The …

No fix yet
Fix from $1,950 2024-06-27
Lollms Web Ui MEDIUM 5.4
CVE-2024-5933

A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows…

No fix yet
Fix from $1,600 2024-06-27
Lollms Web Ui HIGH 7.7
CVE-2024-4498

A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest…

Patch available
Fix from $1,950 2024-06-25
Lollms MEDIUM 6.3
CVE-2024-4499

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerabilit…

No fix yet
Fix from $1,600 2024-06-24