Lollms
Lollms WEB UI: vulnerabilidades y CVE
Lollms WEB UI tiene 46 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 18 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE46
Últimos 12 meses1
Críticas18
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-33340 | Crítica (9.1) | 1.7% | — | 24 mar 2026 | LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in all known existing versions of… |
| CVE-2025-1451 | Alta (7.5) | 0.63% | — | 20 mar 2025 | A vulnerability in parisneo/lollms-webui v13 arises from the server's handling of multipart boundaries in file uploads. The server does not limit or validate the length of the boundary or the characters appended to it,… |
| CVE-2024-9920 | Alta (8.8) | 1.4% | — | 20 mar 2025 | In version v12 of parisneo/lollms-webui, the 'Send file to AL' function allows uploading files with various extensions, including potentially dangerous ones like .py, .sh, .bat, and more. Attackers can exploit this by… |
| CVE-2024-9919 | Alta (8.4) | 0.31% | — | 20 mar 2025 | A missing authentication check in the uninstall endpoint of parisneo/lollms-webui V13 allows attackers to perform unauthorized directory deletions. The /uninstall/{app_name} API endpoint does not call the check_access()… |
| CVE-2024-8898 | Crítica (9.8) | 0.80% | — | 20 mar 2025 | A path traversal vulnerability exists in the `install` and `uninstall` API endpoints of parisneo/lollms-webui version V12 (Strawberry). This vulnerability allows attackers to create or delete directories with arbitrary… |
| CVE-2024-8736 | Media (6.5) | 0.24% | — | 20 mar 2025 | A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF).… |
| CVE-2024-8581 | Crítica (9.1) | 0.95% | — | 20 mar 2025 | A vulnerability in the `upload_app` function of parisneo/lollms-webui V12 (Strawberry) allows an attacker to delete any file or directory on the system. The function does not implement user input filtering with the… |
| CVE-2024-7058 | Media (4.4) | 0.33% | — | 20 mar 2025 | A vulnerability in the sanitize_path function in parisneo/lollms-webui v10 - latest allows an attacker to bypass path sanitization by using relative paths such as './'. This can lead to unauthorized access to… |
| CVE-2024-6986 | Media (5.4) | 0.30% | — | 20 mar 2025 | A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the… |
| CVE-2024-12766 | Alta (7.5) | 0.75% | — | 20 mar 2025 | parisneo/lollms-webui version V13 (feather) suffers from a Server-Side Request Forgery (SSRF) vulnerability in the `POST /api/proxy` REST API. Attackers can exploit this vulnerability to abuse the victim server's… |
| CVE-2024-10047 | Media (5.3) | 1.0% | — | 20 mar 2025 | parisneo/lollms-webui versions v9.9 to the latest are vulnerable to a directory listing vulnerability. An attacker can list arbitrary directories on a Windows system by sending a specially crafted HTTP request to the… |
| CVE-2024-10019 | Media (6.7) | 0.82% | — | 20 mar 2025 | A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal and OS command injection. The function does not properly sanitize the `app_name` parameter, enabling… |
| CVE-2024-6674 | Alta (7.1) | 0.24% | — | 29 oct 2024 | A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services. This… |
| CVE-2024-6673 | Media (6.5) | 0.17% | — | 29 oct 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-webui repository, versions v9.9 to the latest. The endpoint uses the GET… |
| CVE-2024-6959 | Alta (7.1) | 0.22% | — | 13 oct 2024 | A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends a large number of characters to the end of a multipart boundary, the… |
| CVE-2024-6394 | Alta (7.5) | 0.60% | — | 30 sept 2024 | A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation in the `serve_js` function in `app.py`, which allows attackers to… |
| CVE-2024-6040 | Alta (8.8) | 0.17% | — | 1 ago 2024 | In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities. Specifically, the endpoints /reload_binding, /install_binding,… |
| CVE-2024-4897 | Alta (8.4) | 0.45% | — | 2 jul 2024 | parisneo/lollms-webui, in its latest version, is vulnerable to remote code execution due to an insecure dependency on llama-cpp-python version llama_cpp_python-0.2.61+cpuavx2-cp311-cp311-manylinux_2_31_x86_64. The… |
| CVE-2024-6250 | Alta (7.5) | 1.9% | — | 27 jun 2024 | An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `allow_absolute_path=True` allows an… |
| CVE-2024-5933 | Media (5.4) | 0.35% | — | 27 jun 2024 | A Cross-site Scripting (XSS) vulnerability exists in the chat functionality of parisneo/lollms-webui in the latest version. This vulnerability allows an attacker to inject malicious scripts via chat messages, which are… |
| CVE-2024-4498 | Alta (7.7) | 0.49% | — | 25 jun 2024 | A Path Traversal and Remote File Inclusion (RFI) vulnerability exists in the parisneo/lollms-webui application, affecting versions v9.7 to the latest. The vulnerability arises from insufficient input validation in the… |
| CVE-2024-4320 | Crítica (9.8) | 34% | — | 6 jun 2024 | A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler. The… |
| CVE-2024-3322 | Crítica (9.8) | 0.73% | — | 6 jun 2024 | A path traversal vulnerability exists in the 'cyber_security/codeguard' native personality of the parisneo/lollms-webui, affecting versions up to 9.5. The vulnerability arises from the improper limitation of a pathname… |
| CVE-2024-2624 | Crítica (9.8) | 1.4% | — | 6 jun 2024 | A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in… |
| CVE-2024-2548 | Alta (7.5) | 0.88% | — | 6 jun 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files.… |
| CVE-2024-2362 | Crítica (9.1) | 1.1% | — | 6 jun 2024 | A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform. Due to improper validation of file paths between Windows and Linux environments, an attacker can exploit this… |
| CVE-2024-2360 | Crítica (9.8) | 1.9% | — | 6 jun 2024 | parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' and 'PDF LaTeX path' settings. An… |
| CVE-2024-2359 | Crítica (9.8) | 1.2% | — | 6 jun 2024 | A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code. The issue arises from the application's handling of the `/execute_code`… |
| CVE-2024-2288 | Alta (8.3) | 0.26% | — | 6 jun 2024 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the parisneo/lollms-webui repository, affecting versions up to 7.3.0. This… |
| CVE-2024-1873 | Crítica (9.1) | 13% | — | 6 jun 2024 | parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handles file paths, allowing attackers to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.