Vulnerabilities > Llamaindex

DATE CVE VULNERABILITY TITLE RISK
2025-03-20 CVE-2024-12910 Unspecified vulnerability in Llamaindex
A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL.
network
high complexity
llamaindex
5.9
2024-01-22 CVE-2024-23751 SQL Injection vulnerability in Llamaindex
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine.
network
low complexity
llamaindex CWE-89
critical
9.8