Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lollms

First CVE: Mar 30, 2024Active for: 2 yearsTotal CVEs: 67
61.9
VTI Score
TOP TARGET

Lollms is a modestly scoped but prominently deployed large-language-model interface and web UI framework that has accumulated a meaningful volume of vulnerabilities despite its narrow product footprint. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the exposure inherent to internet-facing web interfaces that bridge user input to model execution. Vulnerabilities recur across the core web UI product through a durable pattern of path-traversal variants, cross-site request forgery, and cross-site scripting weaknesses that are characteristic of web applications with insufficient input validation and request-origin verification. Defenders should treat updates to this vendor as high-priority for any deployment exposed to untrusted networks, as the combination of critical severity and exploit availability amplifies the risk surface. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
67
Total CVEs
More Total CVEs than 99% of tracked vendors
5.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lollms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2024
2 years ago
Most Recent CVE
Apr 12, 2026
103 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (67 CVEs).

67 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33340CRITICAL
LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in
Mar 24, 20269.155NOYES
CVE-2024-1520CRITICAL
An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the
Apr 10, 20249.854NONO
CVE-2024-1601CRITICAL
An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message dat
Apr 16, 20249.849NONO
CVE-2024-4322HIGH
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an
May 16, 20247.548NOYES
CVE-2024-4320CRITICAL
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_ex
Jun 6, 20249.846NONO
CVE-2024-1600CRITICAL
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerabili
Apr 10, 20249.343NONO
CVE-2024-3429CRITICAL
A path traversal vulnerability exists in the parisneo/lollms application, specifically within the `sanitize_path_from_endpoint` and `sanitize_path` functions in `lollms_core\lollms
Jun 6, 20249.841NONO
CVE-2026-0560HIGH
A Server-Side Request Forgery (SSRF) vulnerability exists in parisneo/lollms versions prior to 2.2.0, specifically in the `/api/files/export-content` endpoint. The `_download_image
Mar 29, 20267.539NOYES
CVE-2026-1114CRITICAL
In parisneo/lollms version 2.1.0, the application's session management is vulnerable to improper access control due to the use of a weak secret key for signing JSON Web Tokens (JWT
Apr 7, 20269.834NONO
CVE-2026-1115CRITICAL
A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in
Apr 10, 20269.633NONO
View all 67 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products67 CVEs
19%
37%
37%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local14 (20.9%)
Network53 (79.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low66 (98.5%)
High1 (1.5%)
Unknown0 (0.0%)
User Interaction
None46 (68.7%)
Unknown0 (0.0%)
Required21 (31.3%)
Privileges Required
Low9 (13.4%)
High4 (6.0%)
None54 (80.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (67 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
7.5% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lollms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lollms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lollms's Products

View all 2 CNAs →

Top CWEs