📦 Lollms Web Ui

by Lollms

🔍 What is Lollms Web Ui?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-8898

CRITICAL CVSS 9.8 Mar 20, 2025

A path traversal vulnerability in parisneo/lollms-webui version V12 allows attackers to create or delete arbitrary directories on the system by exploiting insufficient input sanitization in the instal...

CVE-2024-8581

CRITICAL CVSS 9.1 Mar 20, 2025

This vulnerability in parisneo/lollms-webui allows attackers to delete any file or directory on the system through path traversal in the upload_app function. It affects users running version V12 (Stra...

CVE-2024-4320

CRITICAL CVSS 9.8 Jun 6, 2024

This CVE-2024-4320 is a critical remote code execution vulnerability in the parisneo/lollms-webui application. Attackers can exploit the '/install_extension' endpoint by manipulating the 'name' parame...

CVE-2024-3322

CRITICAL CVSS 9.8 Jun 6, 2024

This path traversal vulnerability in the lollms-webui's codeguard personality allows attackers to read and overwrite arbitrary files on the system by manipulating the 'code_folder_path' parameter. Att...

CVE-2024-2624

CRITICAL CVSS 9.8 Jun 6, 2024

This vulnerability allows attackers to perform path traversal and arbitrary file uploads in the lollms-webui application by manipulating the 'path' parameter. Attackers can read sensitive personal dat...

CVE-2024-2359

CRITICAL CVSS 9.8 Jun 6, 2024

This vulnerability in parisneo/lollms-webui version 9.3 allows attackers to bypass access restrictions and execute arbitrary code remotely. Attackers exploit the unprotected `/update_setting` endpoint...

CVE-2024-2362

CRITICAL CVSS 9.1 Jun 6, 2024

A path traversal vulnerability in parisneo/lollms-webui version 9.3 on Windows allows attackers to delete any file on the system by exploiting improper path validation in the 'del_preset' endpoint. Th...

CVE-2024-1873

CRITICAL CVSS 9.1 Jun 6, 2024

The CVE-2024-1873 vulnerability in parisneo/lollms-webui allows attackers to perform path traversal attacks through an exposed /select_database endpoint. This enables directory creation anywhere on th...

CVE-2024-4326

CRITICAL CVSS 9.8 May 16, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of parisneo/lollms-webui. Attackers can bypass security controls by manipulating settings to...

CVE-2024-2366

CRITICAL CVSS 9.0 May 16, 2024

This CVE describes a remote code execution vulnerability in the parisneo/lollms-webui application. Attackers can exploit insufficient path sanitization in the reinstall_binding functionality to upload...

CVE-2024-2358

CRITICAL CVSS 9.8 May 16, 2024

A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary code by exploiting insufficient input sanitization in the 'extensions' p...

CVE-2024-1600

CRITICAL CVSS 9.3 Apr 10, 2024

This CVE describes a Local File Inclusion vulnerability in the parisneo/lollms-webui application that allows attackers to read arbitrary files on the server filesystem. Attackers can exploit this by s...

CVE-2024-1520

CRITICAL CVSS 9.8 Apr 10, 2024

This CVE describes a critical OS command injection vulnerability in the lollms-webui application's '/open_code_folder' endpoint. Attackers can execute arbitrary commands on the underlying operating sy...

CVE-2025-1451

HIGH CVSS 7.5 Mar 20, 2025

This vulnerability in parisneo/lollms-webui allows attackers to cause denial of service by sending specially crafted file upload requests with excessively long multipart boundaries. The server fails t...

CVE-2024-9919

HIGH CVSS 8.4 Mar 20, 2025

This vulnerability allows unauthenticated attackers to delete directories via the uninstall API endpoint in parisneo/lollms-webui. Attackers can exploit missing authentication checks to perform unauth...

CVE-2024-9920

HIGH CVSS 8.8 Mar 20, 2025

This vulnerability allows attackers to upload malicious files with dangerous extensions (.py, .sh, .bat, etc.) and execute them via the '/open_file' API endpoint, leading to remote code execution. It ...

CVE-2024-12766

HIGH CVSS 7.5 Mar 20, 2025

This SSRF vulnerability in parisneo/lollms-webui allows attackers to make the server send unauthorized HTTP requests to internal or external systems, potentially accessing sensitive resources. It affe...

CVE-2024-6674

HIGH CVSS 7.1 Oct 29, 2024

A CORS misconfiguration in lollms-webui allows attackers to steal sensitive information like logs, browser sessions, and settings containing private API keys from other services. This vulnerability ca...

CVE-2024-6959

HIGH CVSS 7.1 Oct 13, 2024

This vulnerability in parisneo/lollms-webui version 9.8 allows attackers to cause a Denial of Service (DoS) by uploading specially crafted audio files with manipulated multipart boundaries. The lack o...

CVE-2024-6394

HIGH CVSS 7.5 Sep 30, 2024

A Local File Inclusion vulnerability in parisneo/lollms-webui allows attackers to read arbitrary files on the server through path traversal. This affects all users running versions below v9.8, potenti...

CVE-2024-6040

HIGH CVSS 8.8 Aug 1, 2024

This vulnerability in parisneo/lollms-webui allows attackers to perform Cross-Site Request Forgery (CSRF) attacks against binding management endpoints. Attackers can trick authenticated users into exe...

CVE-2024-4897

HIGH CVSS 8.4 Jul 2, 2024

This vulnerability allows remote attackers to execute arbitrary code on systems running lollms-webui by uploading malicious model files through the binding_zoo feature. The vulnerability stems from an...

CVE-2024-6250

HIGH CVSS 7.5 Jun 27, 2024

An absolute path traversal vulnerability in parisneo/lollms-webui v9.6 allows attackers to read arbitrary files and list directories on Windows systems. This affects users running the vulnerable versi...

CVE-2024-4498

HIGH CVSS 7.7 Jun 25, 2024

This CVE describes a Path Traversal and Remote File Inclusion vulnerability in the parisneo/lollms-webui application that allows attackers to manipulate file paths and include arbitrary files. Success...

CVE-2024-2548

HIGH CVSS 7.5 Jun 6, 2024

A path traversal vulnerability in parisneo/lollms-webui allows attackers to read arbitrary files on Windows systems by exploiting inadequate path validation. This affects users running the latest vers...

CVE-2024-2288

HIGH CVSS 8.3 Jun 6, 2024

A CSRF vulnerability in Lollms WebUI versions up to 7.3.0 allows attackers to change victims' profile pictures without consent. This can lead to denial of service through filesystem overload or enable...

CVE-2024-2178

HIGH CVSS 7.5 Jun 2, 2024

This path traversal vulnerability in parisneo/lollms-webui allows attackers to read arbitrary files by manipulating parameters in the 'copy_to_custom_personas' endpoint. Attackers can use '../' sequen...

CVE-2024-3435

HIGH CVSS 8.4 May 16, 2024

A path traversal vulnerability in the parisneo/lollms-webui application allows attackers to manipulate configuration settings via specially crafted JSON payloads to the 'save_settings' endpoint. This ...

CVE-2024-3126

HIGH CVSS 8.4 May 16, 2024

This CVE describes a command injection vulnerability in the parisneo/lollms-webui application that allows remote attackers to execute arbitrary commands on the host system. The vulnerability affects a...

CVE-2024-1522

HIGH CVSS 8.8 Mar 30, 2024

A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrary OS commands on a victim's system. Attackers can craft malicious webp...

CVE-2024-8736

MEDIUM CVSS 6.5 Mar 20, 2025

This CSRF vulnerability in lollms-webui allows attackers to cause denial of service by exploiting file upload endpoints. Attackers can append extra characters to multipart boundaries, forcing the serv...

CVE-2024-6986

MEDIUM CVSS 5.4 Mar 20, 2025

A stored Cross-site Scripting (XSS) vulnerability in parisneo/lollms-webui allows attackers to inject malicious JavaScript into the System Template configuration. When administrators view the Settings...

CVE-2024-10047

MEDIUM CVSS 5.3 Mar 20, 2025

This vulnerability allows attackers to list arbitrary directories on Windows systems running vulnerable versions of lollms-webui. By sending a specially crafted HTTP request to the /open_file endpoint...

CVE-2024-5933

MEDIUM CVSS 5.4 Jun 27, 2024

This Cross-site Scripting (XSS) vulnerability in parisneo/lollms-webui allows attackers to inject malicious JavaScript via chat messages, which executes in victims' browsers when they view those messa...