OVERVIEW CVE-2026-1115 is a Stored Cross-Site Scripting (XSS) vulnerability affecting parisneo/lollms prior to version 2.2.0. The flaw exists in the social feature's create_post function, where user-supplied content is stored in the database without sanitization, enabling attackers to inject persistent malicious JavaScript code. SEVERITY This vulnerability carries a CRITICAL CVSS v3.0 score of 9.6 with a network-based attack vector requiring minimal complexity and no special privileges. User interaction is required for exploitation, though the impact scope is changed, affecting systems beyond the vulnerable component. Successful exploitation can result in account takeover, session hijacking, and self-propagating wormable attacks that compromise both regular users and administrators viewing the Home Feed. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, as this vulnerability is not listed in the Known Exploited Vulnerabilities (KEV) catalog and is inactive on threat intelligence hot lists. The EPSS score of 0.00046 indicates a low probability of exploitation within the next 30 days relative to other CVEs. However, the straightforward nature of the vulnerability and availability of proof-of-concept information in public disclosures suggest that exploitation code could be readily developed. Organizations running affected versions should prioritize upgrading to version 2.2.0 to remediate this critical risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.1.0CPE matchmatch criteria | cpe:2.3:a:lollms:lollms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.