Vulnerabilities > Lollms > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-6674 Origin Validation Error vulnerability in Lollms web UI
A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, and settings containing private API keys from other services.
network
low complexity
lollms CWE-346
7.1
2024-10-13 CVE-2024-6959 Cross-Site Request Forgery (CSRF) vulnerability in Lollms web UI 9.8
A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file.
network
low complexity
lollms CWE-352
7.1
2024-06-06 CVE-2024-4881 Path Traversal vulnerability in Lollms
A path traversal vulnerability exists in the parisneo/lollms application, affecting version 9.4.0 and potentially earlier versions, but fixed in version 5.9.0.
network
low complexity
lollms CWE-22
7.5
2024-06-06 CVE-2024-2288 Cross-Site Request Forgery (CSRF) vulnerability in Lollms web UI
A Cross-Site Request Forgery (CSRF) vulnerability exists in the profile picture upload functionality of the Lollms application, specifically in the parisneo/lollms-webui repository, affecting versions up to 7.3.0.
network
low complexity
lollms CWE-352
8.3
2024-06-06 CVE-2024-2548 Path Traversal vulnerability in Lollms web UI
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `lollms_core/lollms/server/endpoints/lollms_binding_files_server.py` and `lollms_core/lollms/security.py` files.
network
low complexity
lollms CWE-22
7.5