VendorsLoLLMslollms_web_uiany version
Vulnerabilities

LoLLMs (Lord of Large Language Multimodal Systems) Web UI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2024-1520
OS Command Injection in parisneo/lollms-webui
Published 2024-04-10 · Analyzed
9.8EPSS 0.482
CVE-2024-4320
Remote Code Execution due to LFI in '/install_extension' in parisneo/lollms-webui
Published 2024-06-06 · Modified
9.8EPSS 0.344
CVE-2024-2360
Path Traversal leading to Remote Code Execution in parisneo/lollms-webui
Published 2024-06-06 · Modified
9.8EPSS 0.019
CVE-2024-2624
Path Traversal and Arbitrary File Upload Vulnerability in parisneo/lollms-webui
Published 2024-06-06 · Modified
9.8EPSS 0.014
CVE-2024-2358
Path Traversal leading to Remote Code Execution in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
9.8EPSS 0.011
CVE-2024-4326
Remote Code Execution via `/apply_settings` and `/execute_code` in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
9.8EPSS 0.010
CVE-2024-3322
Path Traversal in parisneo/lollms-webui
Published 2024-06-06 · Modified
9.8EPSS 0.007
CVE-2024-5482
SSRF in add_webpage endpoint in parisneo/lollms-webui
Published 2024-06-06 · Modified
9.8EPSS 0.007
CVE-2024-2361
Arbitrary Upload & Read via Path Traversal in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
9.6EPSS 0.006
CVE-2024-1600
Local File Inclusion in parisneo/lollms-webui
Published 2024-04-10 · Analyzed
9.3EPSS 0.325
CVE-2024-1873
Path Traversal and Denial of Service in parisneo/lollms-webui
Published 2024-06-06 · Modified
9.1EPSS 0.134
CVE-2026-33340
LoLLMs WEBUI has unauthenticated Server-Side Request Forgery (SSRF) in /api/proxy endpoint
Published 2026-03-24 · Analyzed
9.1EPSS 0.017
CVE-2024-2366
Remote Code Execution in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
9.0EPSS 0.007
CVE-2024-1522
Cross-Site Request Forgery (CSRF) Leading to Remote Code Execution in parisneo/lollms-webui
Published 2024-03-30 · Analyzed
8.8EPSS 0.004
CVE-2024-3126
Command Injection in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
8.4EPSS 0.013
CVE-2024-3435
Path Traversal in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
8.4EPSS 0.008
CVE-2024-4897
Remote Code Execution in parisneo/lollms-webui
Published 2024-07-02 · Analyzed
8.4EPSS 0.004
CVE-2024-2288
CSRF File Upload Vulnerability in parisneo/lollms-webui
Published 2024-06-06 · Modified
8.3EPSS 0.003
CVE-2024-6674
Data Leak through CORS Misconfiguration in parisneo/lollms-webui
Published 2024-10-29 · Analyzed
8.1EPSS 0.002
CVE-2024-4322
Path Traversal in parisneo/lollms-webui
Published 2024-05-16 · Analyzed
7.5EPSS 0.310
CVE-2024-2548
Path Traversal in parisneo/lollms-webui
Published 2024-06-06 · Modified
7.5EPSS 0.009
CVE-2024-2178
Path Traversal Vulnerability in parisneo/lollms-webui
Published 2024-06-02 · Analyzed
7.5EPSS 0.006
CVE-2024-2299
Stored Cross-Site Scripting (XSS) via Profile Picture Upload in parisneo/lollms-webui
Published 2024-05-12 · Analyzed
7.4EPSS 0.004
CVE-2024-6673
CSRF Vulnerability in parisneo/lollms-webui
Published 2024-10-29 · Analyzed
6.5EPSS 0.002
CVE-2024-5933
Cross-site Scripting (XSS) in parisneo/lollms-webui
Published 2024-06-27 · Analyzed
6.1EPSS 0.004
CVE-2024-4330
Path Traversal in parisneo/lollms-webui
Published 2024-05-30 · Analyzed
4.0EPSS 0.003