vciy

CVEs we hold for Parisneo/lollms-webui

Records whose assigning authority named Parisneo/lollms-webui as the affected vendor. Newest identifiers first, capped at 200.

CVE-2025-1451Insufficient Patch Leading to DoS in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-9920Unrestricted File Upload and Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-9919Missing Authentication Check in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-8898Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-8736Denial of Service (DoS) via Multipart Boundary in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-8581Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-6986Cross-site Scripting (XSS) in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-6959Denial of Service (DOS) in multipart boundary while uploading file in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-6674Data Leak through CORS Misconfiguration in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-6673CSRF Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-6394Local File Inclusion in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-6250Absolute Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-5933Cross-site Scripting (XSS) in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-5482SSRF in add_webpage endpoint in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-5125XSS and Open Redirect via SVG File Upload in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4897Remote Code Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4841Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4839CSRF in Servers Configurations in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4498Path Traversal and RFI Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4403CSRF in restart_program in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4330Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4328CSRF in clear_personality_files_list in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4326Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4322Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4320Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-4267Remote Code Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-3435Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-3322Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-3126Command Injection in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2624Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2548Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2366Remote Code Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2362Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2361Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2360Path Traversal leading to Remote Code Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2359Improper Neutralization of Special Elements used in an OS Command in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2358Path Traversal leading to Remote Code Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2356Remote Code Execution due to LFI in '/reinstall_extension' in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2299Stored Cross-Site Scripting (XSS) via Profile Picture Upload in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2288CSRF File Upload Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-2178Path Traversal Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1873Path Traversal and Denial of Service in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1646Authentication Bypass in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1602Stored XSS leading to RCE in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1601SQL Injection in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1600Local File Inclusion in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1569Uncontrolled Resource Consumption in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1522Cross-Site Request Forgery (CSRF) Leading to Remote Code Execution in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1520OS Command Injection in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-1511Path Traversal Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-12766SSRF in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-10047Directory Listing Vulnerability in parisneo/lollms-webuiparisneo/lollms-webui
CVE-2024-10019Path Traversal and OS Command Injection in parisneo/lollms-webuiparisneo/lollms-webui

53 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.