VendorsLycheeOrglycheeany version
Vulnerabilities

LycheeOrg Lychee any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2023-52082
Lychee is vulnerable to an SQL Injection in explain DB queries.
Published 2023-12-28 · Modified
9.8EPSS 0.005
CVE-2026-33738
Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)
Published 2026-03-26 · Analyzed
5.4EPSS 0.004
CVE-2026-33537
Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked
Published 2026-03-26 · Analyzed
5.3EPSS 0.003
CVE-2026-39957
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
Published 2026-04-09 · Analyzed
4.3EPSS 0.003
CVE-2026-33644
Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs
Published 2026-03-26 · Analyzed
4.3EPSS 0.003
CVE-2026-22784
Lychee cross-album password propagation on Album unlocking
Published 2026-01-12 · Analyzed
4.3EPSS 0.003