VendorsLycheeOrglycheeall versions
Vulnerabilities

LycheeOrg Lychee

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-52082
Lychee is vulnerable to an SQL Injection in explain DB queries.
Published 2023-12-28 · Modified
9.8EPSS 0.005
CVE-2024-25808
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.
Published 2024-03-22 · Analyzed
8.3EPSS 0.004
CVE-2021-43675
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. The message will contain albumID which is controlled by the user.
Published 2021-12-15 · Modified
6.1EPSS 0.009
CVE-2024-25807
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.
Published 2024-03-22 · Analyzed
6.1EPSS 0.005
CVE-2026-33738
Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)
Published 2026-03-26 · Analyzed
5.4EPSS 0.004
CVE-2026-33537
Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked
Published 2026-03-26 · Analyzed
5.3EPSS 0.003
CVE-2026-39957
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
Published 2026-04-09 · Analyzed
4.3EPSS 0.003
CVE-2026-33644
Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs
Published 2026-03-26 · Analyzed
4.3EPSS 0.003
CVE-2026-22784
Lychee cross-album password propagation on Album unlocking
Published 2026-01-12 · Analyzed
4.3EPSS 0.003