Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

parisneo/lollms-webui — Vulnerabilities & Security Advisories 53

All 53 CVE vulnerabilities found in parisneo/lollms-webui, with AI-generated Chinese analysis, references, and POCs.

This page documents known vulnerabilities for the parisneo/lollms-webui software, specifically focusing on general software weaknesses and security flaws within the project. The collection aggregates reports from various security databases and tracking sources to provide a comprehensive view of the product's security posture over time. Here, you can find a consolidated list of identified issues ranging from remote code execution risks to information disclosure and configuration errors that have been associated with this web interface tool. By visiting this page, security professionals and developers can effectively track advisories released by the vendor or discovered by independent researchers. You can gain a deeper understanding of specific weakness classes that affect the application, such as how improper input validation or dependency management might be exploited. Furthermore, the resource allows users to look up the product's vulnerability history, offering context on when issues were discovered, patched, or remain open. This structured overview helps in assessing the overall risk profile of running the parisneo/lollms-webui in production environments. It serves as a central reference point for evaluating the stability and security integrity of the software before deployment or update. The information presented is intended to support informed decision-making regarding risk mitigation and patch management strategies for stakeholders involved with this specific web user interface for large language models.

Vendor: parisneo

CVE IDTitleCVSSSeverityPublished
CVE-2024-2624 Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webui CWE-29 9.1AICriticalAI2024-06-06
CVE-2024-2548 Path Traversal in parisneo/lollms-webui CWE-36 6.2AIMediumAI2024-06-06
CVE-2024-2362 Path Traversal in parisneo/lollms-webui CWE-36 9.1AICriticalAI2024-06-06
CVE-2024-5482 SSRF in add_webpage endpoint in parisneo/lollms-webui CWE-918 9.8AICriticalAI2024-06-06
CVE-2024-2178 Path Traversal Vulnerability in parisneo/lollms-webui CWE-29 7.5 -2024-06-02
CVE-2024-4330 Path Traversal in parisneo/lollms-webui CWE-23 7.5AIHighAI2024-05-30
CVE-2024-4267 Remote Code Execution in parisneo/lollms-webui CWE-77 9.8AICriticalAI2024-05-22
CVE-2024-2361 Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webui CWE-29 9.1AICriticalAI2024-05-16
CVE-2024-2366 Remote Code Execution in parisneo/lollms-webui CWE-77 9.8AICriticalAI2024-05-16
CVE-2024-3435 Path Traversal in parisneo/lollms-webui CWE-29 9.8AICriticalAI2024-05-16
CVE-2024-3126 Command Injection in parisneo/lollms-webui CWE-78 9.8AICriticalAI2024-05-16
CVE-2024-4326 Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui CWE-15 9.8AICriticalAI2024-05-16
CVE-2024-4322 Path Traversal in parisneo/lollms-webui CWE-29 7.5AIHighAI2024-05-16
CVE-2024-2358 Path Traversal leading to Remote Code Execution in parisneo/lollms-webui CWE-29 9.8AICriticalAI2024-05-16
CVE-2024-2299 Stored Cross-Site Scripting (XSS) via Profile Picture Upload in parisneo/lollms-webui CWE-79 6.1 -2024-05-12
CVE-2024-1569 Uncontrolled Resource Consumption in parisneo/lollms-webui CWE-400 7.5 -2024-04-16
CVE-2024-1646 Authentication Bypass in parisneo/lollms-webui CWE-288 9.8 -2024-04-16
CVE-2024-1601 SQL Injection in parisneo/lollms-webui CWE-89 7.5 -2024-04-16
CVE-2024-1520 OS Command Injection in parisneo/lollms-webui CWE-78 9.8AICriticalAI2024-04-10
CVE-2024-1602 Stored XSS leading to RCE in parisneo/lollms-webui CWE-79 9.0AICriticalAI2024-04-10
CVE-2024-1511 Path Traversal Vulnerability in parisneo/lollms-webui CWE-22 8.8AIHighAI2024-04-10
CVE-2024-1600 Local File Inclusion in parisneo/lollms-webui CWE-98 7.5AIHighAI2024-04-10
CVE-2024-1522 Cross-Site Request Forgery (CSRF) Leading to Remote Code Execution in parisneo/lollms-webui CWE-352 7.4AIHighAI2024-03-30

All 53 known CVE vulnerabilities affecting parisneo/lollms-webui with full Chinese analysis, references, and POCs where available.