Parisneo/lollms
This hub aggregates every CVE we track for Parisneo/lollms, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
AI / MLother
30
CVEs tracked
8
Critical
14
High
0
In CISA KEV
Severity distribution
HIGH14CRITICAL8MEDIUM7LOW1
Monthly trend
0
3
0
0
0
0
4
0
0
0
1
0
0
0
0
0
0
1
3
4
0
0
1
1
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Parisneo/lollms.
- CVE-2026-10595Path Traversal Vulnerability in parisneo/lollms7.5
- CVE-2026-12228Stored XSS in Direct Messages via Prompt Sharing in parisneo/lollms5.4
- CVE-2026-1116Cross-site Scripting (XSS) in parisneo/lollms6.1
- CVE-2026-1115Stored XSS in parisneo/lollms9.6
- CVE-2026-1163Insufficient Session Expiration in parisneo/lollms4.1
- CVE-2026-1114Improper Access Control via Weak JWT Token in parisneo/lollms9.8
- CVE-2026-0558Unauthenticated File Upload in parisneo/lollms9.8
- CVE-2026-0560Server-Side Request Forgery (SSRF) in parisneo/lollms7.5
- CVE-2026-0562Insecure Direct Object Reference (IDOR) in parisneo/lollms8.3
- CVE-2026-1117Improper Access Control in parisneo/lollms8.2
- CVE-2025-6386Timing Attack Vulnerability in parisneo/lollms7.5
- CVE-2024-6982Remote Code Execution in Calculate Function in parisneo/lollms8.4
- CVE-2024-7058Relative Path Traversal in parisneo/lollms-webui4.4
- CVE-2024-9597Path Traversal in parisneo/lollms7.1
- CVE-2024-11302Missing check_access in lollms_binding_infos in parisneo/lollms8.0
Product normalization is registry-driven with AI assist and human review. How it works