Vulnerability index

Browse CVEs

61 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-12228 A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint … Lollms after 2.1.0 Fix from $1,6002026-07-18 MEDIUM 6.1 CVE-2026-1116 A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to versi… Lollms after 2.1.0 Fix from $1,6002026-04-12 CRITICAL 9.6 CVE-2026-1115 A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.… Lollms after 2.1.0 Fix from $2,3002026-04-10 CRITICAL 9.8 CVE-2026-1114 In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key f… Lollms Patch available Fix from $2,3002026-04-07 HIGH 8.3 CVE-2026-0562 A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging… Lollms after 2.1.0 Fix from $1,9502026-03-29 HIGH 7.5 CVE-2026-0560 A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content`… Lollms after 2.1.0 Fix from $1,9502026-03-29 CRITICAL 9.8 CVE-2026-0558 A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/fil… Lollms after 2.1.0 Fix from $2,3002026-03-29 CRITICAL 9.1 CVE-2026-33340EPSS 22% LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner… Lollms Web Ui No fix yet Fix from $2,3002026-03-24 HIGH 7.5 CVE-2025-1451 A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or … Lollms Web Ui No fix yet Fix from $1,9502025-03-20 HIGH 8.8 CVE-2024-9920 In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangero… Lollms Web Ui No fix yet Fix from $1,9502025-03-20 HIGH 8.4 CVE-2024-9919 A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. T… Lollms Web Ui No fix yet Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-8898 A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerab… Lollms Web Ui Patch available Fix from $2,3002025-03-20 CRITICAL 9.1 CVE-2024-8581 A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the syst… Lollms Web Ui Patch available Fix from $2,3002025-03-20 MEDIUM 6.5 CVE-2024-8736 A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability… Lollms Web Ui No fix yet Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-6986 A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper… Lollms Web Ui No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12766 parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attack… Lollms Web Ui No fix yet Fix from $1,9502025-03-20 MEDIUM 6.7 CVE-2024-10019 A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The … Lollms Web Ui No fix yet Fix from $1,6002025-03-20 MEDIUM 5.3 CVE-2024-10047 parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on … Lollms Web Ui No fix yet Fix from $1,6002025-03-20 HIGH 7.3 CVE-2024-5125 parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of … Lollms Webui Patch available Fix from $1,9502024-11-14 HIGH 7.1 CVE-2024-6674 A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, … Lollms Web Ui 10+ Fix from $1,9502024-10-29 MEDIUM 6.5 CVE-2024-6673 A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-web… Lollms Web Ui 10+ Fix from $1,6002024-10-29 CRITICAL 9.0 CVE-2024-6581 A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomp… Lord Of Large Language Models Patch available Fix from $2,3002024-10-29 HIGH 7.1 CVE-2024-6959 A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends… Lollms Web Ui No fix yet Fix from $1,9502024-10-13 HIGH 7.5 CVE-2024-6394 A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation i… Lollms Web Ui No fix yet Fix from $1,9502024-09-30 HIGH 8.8 CVE-2024-6040 In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities.… Lollms Web Ui No fix yet Fix from $1,9502024-08-01 HIGH 8.4 CVE-2024-4897 parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_… Lollms Web Ui 9.8+ Fix from $1,9502024-07-02 HIGH 7.5 CVE-2024-6250 An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The … Lollms Web Ui No fix yet Fix from $1,9502024-06-27 MEDIUM 5.4 CVE-2024-5933 A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows… Lollms Web Ui No fix yet Fix from $1,6002024-06-27 HIGH 7.7 CVE-2024-4498 A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest… Lollms Web Ui Patch available Fix from $1,9502024-06-25 MEDIUM 6.3 CVE-2024-4499 A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerabilit… Lollms No fix yet Fix from $1,6002024-06-24