Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Lylme Spage HIGH 7.3
CVE-2025-4543

A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the file lylme_spage/blob/master/adm…

No fix yet
Fix from $1,950 2025-05-11
Lylme Spage CRITICAL 9.8
CVE-2024-48176

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not b…

Mitigation only
Fix from $2,300 2024-11-05
Lylme Spage CRITICAL 9.8
CVE-2024-48356

LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.

Fix: after 1.6.0
Fix from $2,300 2024-10-28
Lylme Spage CRITICAL 9.8
CVE-2024-48357

LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.

Fix: after 1.6.0
Fix from $2,300 2024-10-28
Lylme Spage HIGH 7.2
CVE-2024-9790

A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The m…

No fix yet
Fix from $1,950 2024-10-10
Lylme Spage HIGH 7.2
CVE-2024-9788

A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. T…

No fix yet
Fix from $1,950 2024-10-10
Lylme Spage HIGH 7.2
CVE-2024-9789

A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. T…

No fix yet
Fix from $1,950 2024-10-10
Lylme Spage CRITICAL 9.1
CVE-2024-36675

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

No fix yet
Fix from $2,300 2024-06-04
Lylme Spage MEDIUM 6.1
CVE-2024-36674

LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.

No fix yet
Fix from $1,600 2024-06-03
Lylme Spage CRITICAL 9.8
CVE-2024-34982

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via upload…

No fix yet
Fix from $2,300 2024-05-17
Lylme Spage CRITICAL 9.8
CVE-2023-45951

lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php.

No fix yet
Fix from $2,300 2023-10-17
Lylme Spage CRITICAL 9.8
CVE-2023-45952

An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading …

No fix yet
Fix from $2,300 2023-10-17