VendorsLichesslilaany version
Vulnerabilities

Lichess Lila any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2025-52186
Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to an internal HTTP client without validation, allowing remote attackers to force the server to send HTTP requests to arbitrary URLs
Published 2025-11-13 · Analyzed
6.5EPSS 0.003
CVE-2026-35208
lichess.org has an Unsanitized Stream Title Injection on /streamer
Published 2026-04-06 · Analyzed
5.4EPSS 0.004