Vulnerability index

Browse CVEs

24 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Lollms Web Ui CRITICAL 9.1
CVE-2026-33340EPSS 22%

LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulner…

No fix yet
Fix from $2,300 2026-03-24
Lollms Web Ui HIGH 7.5
CVE-2025-1451

A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or …

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui HIGH 8.8
CVE-2024-9920

In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangero…

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui HIGH 8.4
CVE-2024-9919

A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. T…

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui MEDIUM 6.5
CVE-2024-8736

A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability…

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui MEDIUM 5.4
CVE-2024-6986

A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper…

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui HIGH 7.5
CVE-2024-12766

parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attack…

No fix yet
Fix from $1,950 2025-03-20
Lollms Web Ui MEDIUM 6.7
CVE-2024-10019

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The …

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui MEDIUM 5.3
CVE-2024-10047

parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on …

No fix yet
Fix from $1,600 2025-03-20
Lollms Web Ui HIGH 7.1
CVE-2024-6959

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends…

No fix yet
Fix from $1,950 2024-10-13
Lollms Web Ui HIGH 7.5
CVE-2024-6394

A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation i…

No fix yet
Fix from $1,950 2024-09-30
Lollms Web Ui HIGH 8.8
CVE-2024-6040

In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities.…

No fix yet
Fix from $1,950 2024-08-01
Lollms Web Ui HIGH 7.5
CVE-2024-6250

An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The …

No fix yet
Fix from $1,950 2024-06-27
Lollms Web Ui MEDIUM 5.4
CVE-2024-5933

A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows…

No fix yet
Fix from $1,600 2024-06-27
Lollms MEDIUM 6.3
CVE-2024-4499

A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerabilit…

No fix yet
Fix from $1,600 2024-06-24
Lollms Webui HIGH 8.8
CVE-2024-4403

A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This vulnerability allows…

No fix yet
Fix from $1,950 2024-06-10
Lollms Web Ui CRITICAL 9.8
CVE-2024-4320EPSS 34%

A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2359

A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issu…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-2360

parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplie…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.1
CVE-2024-2362

A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths betw…

No fix yet
Fix from $2,300 2024-06-06
Lollms Web Ui CRITICAL 9.8
CVE-2024-5482

A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the lates…

No fix yet
Fix from $2,300 2024-06-06
Lollms Webui CRITICAL 9.8
CVE-2024-4267

A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnera…

No fix yet
Fix from $2,300 2024-05-22
Lollms Web Ui MEDIUM 6.1
CVE-2024-1602

parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerability arises due to i…

No fix yet
Fix from $1,600 2024-04-10
Lollms Web Ui CRITICAL 9.8
CVE-2024-1511

The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplied file paths. This …

No fix yet
Fix from $2,300 2024-04-10