Loading HuntDB...

parisneo

4 Products 57 CVEs

CVE Severity Distribution (All Time)

Critical
16
High
28
Medium
12
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 10 CVEs

Recent CVEs

View all
CVE-2024-5125 HIGH 7 months, 2 weeks ago

parisneo/lollms-webui version 9.6 is vulnerable to Cross-Site Scripting (XSS) and Open Redirect due to inadequate input validation and processing of …

CVE-2024-6673 MEDIUM 8 months ago

A Cross-Site Request Forgery (CSRF) vulnerability exists in the `install_comfyui` endpoint of the `lollms_comfyui.py` file in the parisneo/lollms-web…

CVE-2024-6581 MEDIUM 8 months ago

A vulnerability in the discussion image upload function of the Lollms application, version v9.9, allows for the uploading of SVG files. Due to incomp…

CVE-2024-6674 HIGH 8 months ago

A CORS misconfiguration in parisneo/lollms-webui prior to version 10 allows attackers to steal sensitive information such as logs, browser sessions, …

CVE-2024-6959 HIGH 8 months, 3 weeks ago

A vulnerability in parisneo/lollms-webui version 9.8 allows for a Denial of Service (DOS) attack when uploading an audio file. If an attacker appends…

CVE-2024-6985 MEDIUM 8 months, 3 weeks ago

A path traversal vulnerability exists in the api open_personality_folder endpoint of parisneo/lollms-webui. This vulnerability allows an attacker to …

CVE-2024-6971 LOW 8 months, 3 weeks ago

A path traversal vulnerability exists in the parisneo/lollms-webui repository, specifically in the `lollms_file_system.py` file. The functions `add_r…

CVE-2024-6394 HIGH 9 months ago

A Local File Inclusion vulnerability exists in parisneo/lollms-webui versions below v9.8. The vulnerability is due to unverified path concatenation i…

CVE-2024-6040 MEDIUM 11 months ago

In parisneo/lollms-webui version v9.8, the lollms_binding_infos is missing the client_id parameter, which leads to multiple security vulnerabilities.…

CVE-2024-6281 HIGH 11 months, 2 weeks ago

A path traversal vulnerability exists in the `apply_settings` function of parisneo/lollms versions prior to 9.5.1. The `sanitize_path` function does …