📦 Lollms Webui

by Lollms

🔍 What is Lollms Webui?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-4267

CRITICAL CVSS 9.8 May 22, 2024

This CVE describes a critical command injection vulnerability in the parisneo/lollms-webui's 'open_file' module. Attackers can exploit it by providing malicious file paths that execute arbitrary syste...

CVE-2024-1601

CRITICAL CVSS 9.8 Apr 16, 2024

An SQL injection vulnerability in the parisneo/lollms-webui application allows attackers to delete all discussion and message data by sending a crafted HTTP POST request to the /delete_discussion endp...

CVE-2024-5125

HIGH CVSS 7.3 Nov 14, 2024

This vulnerability in lollms-webui version 9.6 allows attackers to upload malicious SVG files containing JavaScript code that executes when rendered, enabling cross-site scripting attacks and open red...

CVE-2024-1646

HIGH CVSS 8.2 Apr 16, 2024

CVE-2024-1646 is an authentication bypass vulnerability in parisneo/lollms-webui that allows unauthorized access to sensitive endpoints. Attackers can exploit inadequate host parameter checking to exe...

CVE-2024-6971

MEDIUM CVSS 4.4 Oct 11, 2024

A path traversal vulnerability in the lollms-webui allows attackers to perform vectorize operations on arbitrary .sqlite files on the victim's computer. This can lead to unauthorized package installat...