Lollms Webui
Vendor:
First CVE: Mar 30, 2024 · Active for 2 years
55
Total CVEs
More Total CVEs than 88% of tracked products
18.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Lollms Webui over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2024
2 years ago
Most Recent CVE
Mar 24, 2026
126 days ago
CVE Severity & Scoring
Lollms Webui55 CVEs
18%
40%
36%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local12 (21.8%)
Network43 (78.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (98.2%)
High1 (1.8%)
Unknown0 (0.0%)
User Interaction
None38 (69.1%)
Unknown0 (0.0%)
Required17 (30.9%)
Privileges Required
Low6 (10.9%)
High3 (5.5%)
None46 (83.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (55 CVEs).
55 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-33340CRITICAL LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in | Mar 24, 2026 | 9.1 | 55 | NO | YES |
CVE-2024-1520CRITICAL An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the | Apr 10, 2024 | 9.8 | 54 | NO | NO |
CVE-2024-1601CRITICAL An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message dat | Apr 16, 2024 | 9.8 | 49 | NO | NO |
CVE-2024-4322HIGH A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an | May 16, 2024 | 7.5 | 48 | NO | YES |
CVE-2024-4320CRITICAL A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_ex | Jun 6, 2024 | 9.8 | 46 | NO | NO |
CVE-2024-1600CRITICAL A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerabili | Apr 10, 2024 | 9.3 | 44 | NO | NO |
CVE-2024-6250HIGH An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with ` | Jun 27, 2024 | 7.5 | 32 | NO | YES |
CVE-2024-1873CRITICAL parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handle | Jun 6, 2024 | 9.1 | 31 | NO | NO |
CVE-2024-2360CRITICAL parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path' | Jun 6, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-4267CRITICAL A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper n | May 22, 2024 | 9.8 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (55 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
7.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (55 CVEs).
Media Mentions
Signals from CVEs in this product scope (55 CVEs).
Top CNAs Publishing CVEs For Lollms Webui
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.9 | 1 | 5.3 | 0.9% | 0 | 0 |
| 9.8 | 5 | 6.6 | 0.3% | 0 | 0 |
| 9.7 | 1 | 7.7 | 0.5% | 0 | 0 |
| 9.6 | 5 | 6.0 | 0.7% | 0 | 2 |
| 9.5 | 1 | 9.8 | 1.5% | 0 | 0 |
| 9.3 | 2 | 9.4 | 1.2% | 0 | 0 |
| 9.1 | 2 | 8.7 | 20.6% | 0 | 0 |
| 9.0 | 3 | 8.6 | 14.0% | 0 | 0 |
| 13 | 3 | 7.8 | 0.5% | 0 | 0 |
| 12 | 5 | 8.2 | 0.8% | 0 | 0 |
| 10 | 1 | 4.4 | 0.3% | 0 | 0 |