VendorsLycheeOrglychee3.1.6
Vulnerabilities

LycheeOrg Lychee 3.1.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2024-25808
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.
Published 2024-03-22 · Analyzed
8.3EPSS 0.004
CVE-2024-25807
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.
Published 2024-03-22 · Analyzed
6.1EPSS 0.005