📦 Lylme Spage

by Lylme

🔍 What is Lylme Spage?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-48176

CRITICAL CVSS 9.8 Nov 5, 2024

Lylme Spage v1.9.5 has an authentication bypass vulnerability due to missing login attempt limits and static verification codes. Attackers can brute-force credentials to gain unauthorized access to th...

CVE-2024-48356

CRITICAL CVSS 9.8 Oct 28, 2024

LyLme Spage versions up to 1.6.0 contain a SQL injection vulnerability in the /admin/group.php endpoint. This allows attackers to execute arbitrary SQL commands on the database. All users running vuln...

CVE-2024-48357

CRITICAL CVSS 9.8 Oct 28, 2024

LyLme Spage versions 1.2.0 through 1.6.0 contain a SQL injection vulnerability in the /admin/apply.php endpoint. This allows attackers to execute arbitrary SQL commands on the database, potentially co...

CVE-2024-36675

CRITICAL CVSS 9.1 Jun 4, 2024

LyLme_spage v1.9.5 contains a Server-Side Request Forgery (SSRF) vulnerability in the get_head function that allows attackers to make arbitrary HTTP requests from the vulnerable server. This can lead ...

CVE-2023-45951

CRITICAL CVSS 9.8 Oct 17, 2023

CVE-2023-45951 is a SQL injection vulnerability in lylme_spage v1.7.0 that allows attackers to execute arbitrary SQL commands via the $userip parameter. This affects all users running the vulnerable v...

CVE-2025-4543

HIGH CVSS 7.3 May 11, 2025

This critical SQL injection vulnerability in LyLme Spage 2.1 allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in admin/ajax_link.php. Attackers can potentially read, ...

CVE-2024-9790

MEDIUM CVSS 4.7 Oct 10, 2024

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /admin/sou.php file in LyLme_spage 1.9.5. Attackers can potentially access, modify, or delete...

CVE-2024-9788

MEDIUM CVSS 4.7 Oct 10, 2024

This vulnerability allows remote attackers to execute SQL injection attacks via the 'id' parameter in the /admin/tag.php file in LyLme_spage 1.9.5. Attackers can potentially read, modify, or delete da...