Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
84 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 1.0% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the /open_file endpoint. | |
| Modificada | Media (6.7) | 0.82% | — | Lollms WEB UI | 20/3/2025 | 17/6/2026 | A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the `app_name` parameter, enabling an attacker to upload a malicious `server.py` file and execute arbitrary code by exploiting the… | |
| Modificada | Alta (7.3) | 0.32% | — | Lollms-webui | 14/11/2024 | 17/6/2026 | parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of SVG files during the upload process. The XSS vulnerability allows attackers to embed malicious JavaScript code within SVG files, which is executed upon rendering, leading… | |
| Analizada | Alta (7.1) | 0.24% | — | Lollms WEB UI | 29/10/2024 | 17/6/2026 | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This vulnerability can also enable attackers to perform actions on behalf of a user, such as deleting a… | |
| Analizada | Media (6.5) | 0.17% | — | Lollms WEB UI | 29/10/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET method without requiring a client ID, allowing an attacker to trick a victim into installing… | |
| Analizada | Crítica (9) | 0.62% | — | Lollms Lord OF Large Language Models | 29/10/2024 | 17/6/2026 | A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomplete filtering in the sanitize_svg function, this can lead to cross-site scripting (XSS) vulnerabilities, which in turn pose a risk of remote code execution. The… | |
| Modificada | Alta (7.1) | 0.22% | — | Lollms WEB UI | 13/10/2024 | 17/6/2026 | A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the system will continuously process each character, rendering lollms-webui inaccessible. This issue is… | |
| Analizada | Media (4.4) | 0.36% | — | Lollms | 11/10/2024 | 17/6/2026 | A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer, even though sanitize_path is set. The issue arises due to improper sanitization of the… | |
| Analizada | Media (4.4) | 0.32% | — | Lollms-webui | 11/10/2024 | 17/6/2026 | A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_rag_database`, `toggle_mount_rag_database`, and `vectorize_folder` do not implement security measures such as `sanitize_path_from_endpoint` or `sanitize_path`. This allows… | |
| Analizada | Alta (7.5) | 0.60% | — | Lollms WEB UI | 30/9/2024 | 17/6/2026 | A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to perform path traversal attacks. This can lead to unauthorized access to arbitrary files on the server,… | |
| Modificada | Alta (8.8) | 0.17% | — | Lollms WEB UI | 1/8/2024 | 17/6/2026 | In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding, /reinstall_binding, /unInstall_binding, /set_active_binding_settings, and /update_binding_settings are… | |
| Aplazada | Alta (7.3) | 0.27% | — | Parisneo LollmsAI | 20/7/2024 | 17/6/2026 | A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does not adequately secure the `discussion_db_name` parameter, allowing attackers to manipulate the path and potentially write to important system folders. | |
| Analizada | Alta (8.4) | 0.45% | — | Lollms WEB UI | 2/7/2024 | 17/6/2026 | parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The vulnerability arises from the application's 'binding_zoo' feature, which allows attackers to upload and… | |
| Analizada | Alta (7.5) | 1.9% | 💥 Exploit | Lollms WEB UI | 27/6/2024 | 17/6/2026 | An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an attacker to access arbitrary files and directories on a Windows system. This vulnerability can be… | |
| Aplazada | Alta (7.3) | 0.52% | — | Parisneo LollmsAI | 27/6/2024 | 17/6/2026 | A path traversal vulnerability exists in the XTTS server of the parisneo/lollms package version v9.6. This vulnerability allows an attacker to write audio files to arbitrary locations on the system and enumerate file paths. The issue arises from improper validation of user-provided file paths in the `tts_to_file`… | |
| Aplazada | Alta (8.6) | 0.64% | — | LollmsAI | 27/6/2024 | 17/6/2026 | A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an unauthenticated root folder settings change. Although the read file endpoint is protected against path traversals, this protection can be bypassed by changing… | |
| Analizada | Media (5.4) | 0.35% | — | Lollms WEB UI | 27/6/2024 | 17/6/2026 | A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are then executed in the context of the user's browser. | |
| Aplazada | Alta (7.4) | 0.45% | — | Parisneo LollmsAI | 27/6/2024 | 17/6/2026 | A path traversal vulnerability in the `/set_personality_config` endpoint of parisneo/lollms version 9.4.0 allows an attacker to overwrite the `configs/config.yaml` file. This can lead to remote code execution by changing server configuration properties such as `force_accept_remote_access` and `turn_on_code_validation`. | |
| Analizada | Alta (7.7) | 0.49% | — | Lollms WEB UI | 25/6/2024 | 17/6/2026 | A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the `/apply_settings` function, allowing an attacker to manipulate the `discussion_db_name` parameter to… | |
| Analizada | Baja (3.3) | 0.16% | — | Lollms-webui | 24/6/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the 'Servers Configurations' function of the parisneo/lollms-webui, versions 9.6 to the latest. The affected functions include Elastic search Service (under construction), XTTS service, Petals service, vLLM service, and Motion Ctrl service, which lack CSRF… | |
| Modificada | Media (6.3) | 0.18% | — | Lollms | 24/6/2024 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user into visiting a malicious webpage, which can then trigger arbitrary LoLLMS-XTTS API requests. This… | |
| Modificada | Baja (3.3) | 0.45% | 💥 PoC | Lollms | 24/6/2024 | 17/6/2026 | A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker to inject arbitrary commands by manipulating the env_name and python_version… | |
| Analizada | Baja (3.3) | 0.67% | 💥 Exploit | Lollms-webui | 23/6/2024 | 17/6/2026 | A Path Traversal vulnerability exists in the parisneo/lollms-webui, specifically within the 'add_reference_to_local_mode' function due to the lack of input sanitization. This vulnerability affects versions v9.6 to the latest. By exploiting this vulnerability, an attacker can predict the folders, subfolders, and files… | |
| Aplazada | Crítica (9.8) | 1.2% | — | Parisneo LollmsAI | 22/6/2024 | 17/6/2026 | CVE-2024-4320 describes a vulnerability in the parisneo/lollms software, specifically within the `ExtensionBuilder().build_extension()` function. The vulnerability arises from the `/mount_extension` endpoint, where a path traversal issue allows attackers to navigate beyond the intended directory structure. This is… | |
| Aplazada | Crítica (9.1) | 1.0% | — | Parisneo LollmsAI | 12/6/2024 | 17/6/2026 | parisneo/lollms version 9.5 is vulnerable to Local File Inclusion (LFI) attacks due to insufficient path sanitization. The `sanitize_path_from_endpoint` function fails to properly sanitize Windows-style paths (backward slash `\`), allowing attackers to perform directory traversal attacks on Windows systems. This… |