Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

parisneo/lollms — Vulnerabilities & Security Advisories 30

All 30 CVE vulnerabilities found in parisneo/lollms, with AI-generated Chinese analysis, references, and POCs.

This aggregation page collects security advisories for the parisneo/lollms product, which is a lightweight, local large language model server. The page lists reported vulnerabilities affecting this specific software artifact, covering all publicly disclosed issues up to the present day. Readers can use this resource to track the vendor's advisory history, analyze recurring weakness patterns within the lollms codebase, and evaluate the product's security posture over time. By reviewing these entries, teams can identify recurring themes, such as input validation gaps or dependency-related risks, without searching through individual CVE records. The collection serves as a centralized reference point for developers and security analysts who need to monitor the security evolution of the parisneo/lollms project.

Vendor: parisneo

CVE ID Title CVSS Severity Published
CVE-2026-10595 Path Traversal Vulnerability in parisneo/lollms CWE-23 - - 2026-08-09
CVE-2026-12228 Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms CWE-79 - - 2026-07-18
CVE-2026-1116 Cross-site Scripting (XSS) in parisneo/lollms CWE-79 5.4AI Medium AI 2026-04-12
CVE-2026-1115 Stored XSS in parisneo/lollms CWE-79 6.1AI Medium AI 2026-04-10
CVE-2026-1163 Insufficient Session Expiration in parisneo/lollms CWE-613 9.1AI Critical AI 2026-04-08
CVE-2026-1114 Improper Access Control via Weak JWT Token in parisneo/lollms CWE-284 9.8AI Critical AI 2026-04-07
CVE-2026-0558 Unauthenticated File Upload in parisneo/lollms CWE-287 9.8 - 2026-03-29
CVE-2026-0560 Server-Side Request Forgery (SSRF) in parisneo/lollms CWE-918 9.8 - 2026-03-29
CVE-2026-0562 Insecure Direct Object Reference (IDOR) in parisneo/lollms CWE-863 6.5 - 2026-03-29
CVE-2026-1117 Improper Access Control in parisneo/lollms CWE-284 8.1AI High AI 2026-02-02
CVE-2025-6386 Timing Attack Vulnerability in parisneo/lollms CWE-203 5.9AI Medium AI 2025-07-07
CVE-2024-6982 Remote Code Execution in Calculate Function in parisneo/lollms CWE-94 9.8 - 2025-03-20
CVE-2024-7058 Relative Path Traversal in parisneo/lollms-webui CWE-23 6.5 - 2025-03-20
CVE-2024-9597 Path Traversal in parisneo/lollms CWE-22 9.1 - 2025-03-20
CVE-2024-11302 Missing check_access in lollms_binding_infos in parisneo/lollms CWE-304 9.1 - 2025-03-20
CVE-2024-6581 Remote Code Execution due to Stored XSS in parisneo/lollms CWE-79 8.2AI High AI 2024-10-29
CVE-2024-6985 Path Traversal in api open_personality_folder in parisneo/lollms-webui CWE-23 7.5AI High AI 2024-10-11
CVE-2024-6971 Path Traversal in parisneo/lollms-webui CWE-22 8.4AI High AI 2024-10-11
CVE-2024-6040 Missing client_id in parisneo/lollms-webui CWE-352 8.8AI High AI 2024-08-01
CVE-2024-6281 Path Traversal in parisneo/lollms CWE-22 7.5 - 2024-07-20
CVE-2024-6139 Path Traversal in parisneo/lollms CWE-29 5.3AI Medium AI 2024-06-27
CVE-2024-5824 Path Traversal in parisneo/lollms CWE-22 9.8AI Critical AI 2024-06-27
CVE-2024-6085 Path Traversal in parisneo/lollms CWE-22 9.1AI Critical AI 2024-06-27
CVE-2024-4499 CSRF Vulnerability in parisneo/lollms XTTS Server CWE-352 8.1AI High AI 2024-06-24
CVE-2024-3121 Remote Code Execution in create_conda_env function in parisneo/lollms CWE-94 9.8 - 2024-06-24
CVE-2024-5443 Remote Code Execution via Path Traversal in parisneo/lollms CWE-29 9.1 - 2024-06-22
CVE-2024-4315 LFI Vulnerability due to Lack of Path Sanitization in parisneo/lollms CWE-22 9.8AI Critical AI 2024-06-12
CVE-2024-3429 Path Traversal in parisneo/lollms CWE-29 9.1AI Critical AI 2024-06-06
CVE-2024-4881 Path Traversal in parisneo/lollms CWE-36 9.1AI Critical AI 2024-06-06
CVE-2024-4078 Arbitrary Code Execution in parisneo/lollms CWE-77 9.8AI Critical AI 2024-05-16

All 30 known CVE vulnerabilities affecting parisneo/lollms with full Chinese analysis, references, and POCs where available.