Vulnerabilities > Lollms

DATE CVE VULNERABILITY TITLE RISK
2024-06-06 CVE-2024-4320 Path Traversal vulnerability in Lollms web UI
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_extension")` route handler.
network
low complexity
lollms CWE-22
critical
9.8
2024-06-06 CVE-2024-4881 Path Traversal vulnerability in Lollms
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0.
network
low complexity
lollms CWE-22
7.5
2024-06-06 CVE-2024-1873 Unspecified vulnerability in Lollms web UI
parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0.
network
low complexity
lollms
critical
9.1
2024-06-06 CVE-2024-2288 Cross-Site Request Forgery (CSRF) vulnerability in Lollms web UI
A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the parisneo/lollms-webui repository, affecting versions up to 7.3.0.
network
low complexity
lollms CWE-352
8.3
2024-06-06 CVE-2024-2359 OS Command Injection vulnerability in Lollms web UI 9.3
A vulnerability in the parisneo/lollms-webui version 9.3 allows attackers to bypass intended access restrictions and execute arbitrary code.
network
low complexity
lollms CWE-78
critical
9.8
2024-06-06 CVE-2024-2360 Path Traversal vulnerability in Lollms web UI
parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' and 'PDF LaTeX path' settings.
network
low complexity
lollms CWE-22
critical
9.8
2024-06-06 CVE-2024-2362 Path Traversal vulnerability in Lollms web UI 9.3
A path traversal vulnerability exists in the parisneo/lollms-webui version 9.3 on the Windows platform.
network
low complexity
lollms CWE-22
critical
9.1
2024-06-06 CVE-2024-2548 Path Traversal vulnerability in Lollms web UI
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files.
network
low complexity
lollms CWE-22
7.5
2024-06-06 CVE-2024-2624 Path Traversal vulnerability in Lollms web UI
A path traversal and arbitrary file upload vulnerability exists in the parisneo/lollms-webui application, specifically within the `@router.get("/switch_personal_path")` endpoint in `./lollms-webui/lollms_core/lollms/server/endpoints/lollms_user.py`.
network
low complexity
lollms CWE-22
critical
9.8
2024-06-06 CVE-2024-5482 Server-Side Request Forgery (SSRF) vulnerability in Lollms web UI
A Server-Side Request Forgery (SSRF) vulnerability exists in the 'add_webpage' endpoint of the parisneo/lollms-webui application, affecting the latest version.
network
low complexity
lollms CWE-918
critical
9.8