Product
lollms web ui
67 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-1116
CVE-2026-1115
CVE-2026-1114
CVE-2026-0562
CVE-2026-0560
CVE-2026-0558
CVE-2026-33340
CVE-2025-1451
CVE-2024-9920
CVE-2024-9919
CVE-2024-8898
CVE-2024-8736
CVE-2024-8581
CVE-2024-7058
CVE-2024-6986
CVE-2024-12766
CVE-2024-10047
CVE-2024-10019
CVE-2024-5125
CVE-2024-6674
CVE-2024-6673
CVE-2024-6581
CVE-2024-6959
CVE-2024-6985
CVE-2024-6971
CVE-2024-6394
CVE-2024-6040
CVE-2024-4897
CVE-2024-6250
CVE-2024-5933
CVE-2024-4498
CVE-2024-4839
CVE-2024-4499
CVE-2024-3121
CVE-2024-4841
CVE-2024-4403
CVE-2024-4881
CVE-2024-4320
CVE-2024-3429
CVE-2024-3322
CVE-2024-2624
CVE-2024-2548
CVE-2024-2362
CVE-2024-2360
CVE-2024-2359
CVE-2024-2288
CVE-2024-1873
CVE-2024-5482
CVE-2024-2178
CVE-2024-4330
CVE-2024-4267
CVE-2024-4326
CVE-2024-4322
CVE-2024-3435
CVE-2024-3126
CVE-2024-2366
CVE-2024-2361
CVE-2024-2358
CVE-2024-2299
CVE-2024-1646
CVE-2024-1601
CVE-2024-1569
CVE-2024-1602
CVE-2024-1600
CVE-2024-1520
CVE-2024-1511
CVE-2024-1522
<= 2.1.0
A Cross-site Scripting (XSS) vulnerability was identified in the
from_dict method of the AppLollmsMessage class in parisneo/lo<= 2.1.0
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest ve
all versions
In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of
<= 2.1.0
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend
<= 2.1.0
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/fi
<= 2.1.0
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files th
all versions
LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Fo
all versions
A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server
all versions
In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including
all versions
A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized dir
all versions
A path traversal vulnerability exists in the
install and uninstall API endpoints of parisneo/lollms-webui version V12 (Strawbeall versions
A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry)
all versions
A vulnerability in the
upload_app function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or diall versions
A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization
all versions
A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is
all versions
parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/prox
all versions
parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitr
all versions
A vulnerability in the
start_app_server function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS commall versions
parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation
< 10
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs,
< 10
A Cross-Site Request Forgery (CSRF) vulnerability exists in the
install_comfyui endpoint of the lollms_comfyui.py file in theall versions
A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG f
all versions
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If
< 5.9.0
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability all
all versions
A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the
lollms_file_system.py file. Tall versions
A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified p
all versions
In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple securi
< 9.8
parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-py
all versions
An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the
open_file endpoint of `lollmsall versions
A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This v
all versions
A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions
all versions
A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, ve
all versions
A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS polic
all versions
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. Th
all versions
A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function
all versions
A Cross-Site Request Forgery (CSRF) vulnerability exists in the restart_program function of the parisneo/lollms-webui v9.6. This v
< 5.9.0
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions
all versions
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application,
< 9.6
A path traversal vulnerability exists in the parisneo/lollms application, specifically within the
sanitize_path_from_endpoint an< 9.5
A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting
< 9.4
A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the
< 9.5
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server
all versions
A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation
all versions
parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitizat
all versions
A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbit
< 9.3
A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, sp
all versions
parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed
/select_database endpointall versions
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application,
< 9.4
A path traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'copy_to_custom_personas' endpoint in
>= 9.6 and < 9.8
A path traversal vulnerability was identified in the parisneo/lollms-webui repository, specifically within version 9.6. The vulner
all versions
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, versi
< 9.5
A vulnerability in parisneo/lollms-webui versions up to 9.3 allows remote attackers to execute arbitrary code. The vulnerability s
< 9.8
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the
/list_personalities endp< 9.5
A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions
< 9.5
A command injection vulnerability exists in the 'run_xtts_api_server' function of the parisneo/lollms-webui application, specifica
< 9.5
A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding f
< 9.5
A vulnerability in the parisneo/lollms-webui allows for arbitrary file upload and read due to insufficient sanitization of user-su
< 9.5
A path traversal vulnerability in the '/apply_settings' endpoint of parisneo/lollms-webui allows attackers to execute arbitrary co
< 9.5
A stored Cross-Site Scripting (XSS) vulnerability exists in the parisneo/lollms-webui application due to improper validation of up
< 9.3
parisneo/lollms-webui is vulnerable to authentication bypass due to insufficient protection over sensitive endpoints. The applicat
all versions
An SQL injection vulnerability exists in the
delete_discussion() function of the parisneo/lollms-webui application, allowing anall versions
parisneo/lollms-webui is vulnerable to a denial of service (DoS) attack due to uncontrolled resource consumption. Attackers can ex
all versions
parisneo/lollms-webui is vulnerable to stored Cross-Site Scripting (XSS) that leads to Remote Code Execution (RCE). The vulnerabil
>= 9.0 and < 9.6
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalitie
>= 9.0 and < 9.2
An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to
all versions
The parisneo/lollms-webui repository is susceptible to a path traversal vulnerability due to inadequate validation of user-supplie
>= 9.0 and <= 9.2
A Cross-Site Request Forgery (CSRF) vulnerability in the parisneo/lollms-webui project allows remote attackers to execute arbitrar