« Back to list

Lollms

Lollms: vulnerabilities and CVEs

Lollms has 13 published vulnerabilities, 7 of them in the last 12 months. 4 are rated critical and 0 are listed by CISA as actively exploited.

CVEs13
Last 12 months7
Critical4
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-12228Medium (5.4)0.33%—Jul 18, 2026
A stored cross-site scripting (XSS) vulnerability exists in the `POST /api/prompts/share` endpoint of parisneo/lollms (latest version). The endpoint stores attacker-controlled `prompt_content` into…
CVE-2026-1116Medium (6.1)0.26%—Apr 12, 2026
A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or…
CVE-2026-1115Critical (9.6)1.3%—Apr 10, 2026
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within…
CVE-2026-1114Critical (9.8)0.54%—Apr 7, 2026
In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT). This vulnerability allows an…
CVE-2026-0562High (8.3)0.27%—Mar 29, 2026
A critical security vulnerability in parisneo/lollms versions up to 2.2.0 allows any authenticated user to accept or reject friend requests belonging to other users. The `respond_request()` function in…
CVE-2026-0560High (7.5)1.8%—Mar 29, 2026
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image_to_temp()` function in…
CVE-2026-0558Critical (9.8)2.0%—Mar 29, 2026
A vulnerability in parisneo/lollms, up to and including version 2.2.0, allows unauthenticated users to upload and process files through the `/api/files/extract-text` endpoint. This endpoint does not enforce…
CVE-2024-6985Medium (4.4)0.36%—Oct 11, 2024
A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to read any folder in the personality_folder on the victim's computer,…
CVE-2024-6085High (8.6)0.64%—Jun 27, 2024
A path traversal vulnerability exists in the XTTS server included in the lollms package, version v9.6. This vulnerability arises from the ability to perform an unauthenticated root folder settings change. Although the…
CVE-2024-4499Medium (6.3)0.18%—Jun 24, 2024
A Cross-Site Request Forgery (CSRF) vulnerability exists in the XTTS server of parisneo/lollms version 9.6 due to a lax CORS policy. The vulnerability allows attackers to perform unauthorized actions by tricking a user…
CVE-2024-3121Low (3.3)0.45%—Jun 24, 2024
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which…
CVE-2024-4881High (7.5)0.89%—Jun 6, 2024
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0. The vulnerability arises due to improper validation of file…
CVE-2024-3429Critical (9.8)28%—Jun 6, 2024
A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms\security.py`. This vulnerability…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application3
  2. T1059.007 JavaScript1
  3. T1078 Valid Accounts1
  4. T1078.001 Default Accounts1
  5. T1090.004 Domain Fronting1
  6. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Lollms