Lollms Webui

Vendor:

First CVE: Mar 30, 2024 · Active for 2 years

55
Total CVEs
More Total CVEs than 88% of tracked products
18.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Lollms Webui over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2024
2 years ago
Most Recent CVE
Mar 24, 2026
126 days ago

CVE Severity & Scoring

Lollms Webui55 CVEs
All CVEs353,240 CVEs
LowMediumHighCritical
Attack Vector
Local12 (21.8%)
Network43 (78.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low54 (98.2%)
High1 (1.8%)
Unknown0 (0.0%)
User Interaction
None38 (69.1%)
Unknown0 (0.0%)
Required17 (30.9%)
Privileges Required
Low6 (10.9%)
High3 (5.5%)
None46 (83.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (55 CVEs).

55 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
LoLLMs WEBUI provides the Web user interface for Lord of Large Language and Multi modal Systems. A critical Server-Side Request Forgery (SSRF) vulnerability has been identified in
Mar 24, 20269.155NOYES
An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the
Apr 10, 20249.854NONO
An SQL injection vulnerability exists in the `delete_discussion()` function of the parisneo/lollms-webui application, allowing an attacker to delete all discussions and message dat
Apr 16, 20249.849NONO
A path traversal vulnerability exists in the parisneo/lollms-webui application, specifically within the `/list_personalities` endpoint. By manipulating the `category` parameter, an
May 16, 20247.548NOYES
A remote code execution (RCE) vulnerability exists in the '/install_extension' endpoint of the parisneo/lollms-webui application, specifically within the `@router.post("/install_ex
Jun 6, 20249.846NONO
A Local File Inclusion (LFI) vulnerability exists in the parisneo/lollms-webui application, specifically within the `/personalities` route. An attacker can exploit this vulnerabili
Apr 10, 20249.344NONO
An absolute path traversal vulnerability exists in parisneo/lollms-webui v9.6, specifically in the `open_file` endpoint of `lollms_advanced.py`. The `sanitize_path` function with `
Jun 27, 20247.532NOYES
parisneo/lollms-webui is vulnerable to path traversal and denial of service attacks due to an exposed `/select_database` endpoint in version a9d16b0. The endpoint improperly handle
Jun 6, 20249.131NONO
parisneo/lollms-webui is vulnerable to path traversal attacks that can lead to remote code execution due to insufficient sanitization of user-supplied input in the 'Database path'
Jun 6, 20249.828NONO
A remote code execution (RCE) vulnerability exists in the parisneo/lollms-webui, specifically within the 'open_file' module, version 9.5. The vulnerability arises due to improper n
May 22, 20249.827NONO

Exploit Exposure

Signals from CVEs in this product scope (55 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
7.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (55 CVEs).

Media Mentions

Signals from CVEs in this product scope (55 CVEs).

Top CNAs Publishing CVEs For Lollms Webui

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.915.30.9%00
9.856.60.3%00
9.717.70.5%00
9.656.00.7%02
9.519.81.5%00
9.329.41.2%00
9.128.720.6%00
9.038.614.0%00
1337.80.5%00
1258.20.8%00
1014.40.3%00