lollms web ui
56 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
install and uninstall API endpoints of parisneo/lollms-webui version V12 (Strawbeupload_app function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or distart_app_server function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS comminstall_comfyui endpoint of the lollms_comfyui.py file in thelollms_file_system.py file. Topen_file endpoint of `lollms/select_database endpoint/list_personalities endpdelete_discussion() function of the parisneo/lollms-webui application, allowing an