Lycheeorg maintains a specialized photo-management and gallery platform (Lychee) that, despite a narrow product footprint, occupies a notable niche in self-hosted and shared content applications. Vulnerabilities affecting the vendor skew toward serious outcomes and concentrate in application-layer weaknesses that recur across web-facing platforms: cross-site scripting, SQL injection, server-side request forgery, cross-site request forgery, and improper authorization controls that reflect typical input-handling and session-management exposures in PHP-based web applications. Current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lycheeorg over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-52082CRITICAL Lychee is a free photo-management tool. Prior to 5.0.2, Lychee is vulnerable to an SQL injection on any binding when using mysql/mariadb. This injection is only active for users w | Dec 28, 2023 | 9.8 | 27 | NO | NO |
CVE-2024-25808HIGH Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function. | Mar 22, 2024 | 8.3 | 21 | NO | NO |
CVE-2021-43675MEDIUM Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php. The function exit will terminate the script and print the message to the user. T | Dec 15, 2021 | 6.1 | 21 | NO | NO |
CVE-2026-33738MEDIUM Lychee is a free, open-source photo-management tool. Prior to version 7.5.3, the photo `description` field is stored without HTML sanitization and rendered using `{!! $item->summar | Mar 26, 2026 | 5.4 | 19 | NO | NO |
CVE-2026-33537MEDIUM Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::fromUrl`) contains an incomplete IP validation check that fails | Mar 26, 2026 | 5.0 | 19 | NO | NO |
CVE-2026-39957MEDIUM Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController::listAll() causes the orWhereNotNull('user_group_id') clause | Apr 9, 2026 | 4.3 | 18 | NO | NO |
CVE-2026-22784MEDIUM Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's album password unlock functionality that allows users to gain | Jan 12, 2026 | 4.3 | 18 | NO | NO |
CVE-2024-25807MEDIUM Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating a | Mar 22, 2024 | 6.1 | 18 | NO | NO |
CVE-2026-33644MEDIUM Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` can be bypassed using DNS rebinding. The IP validation check | Mar 26, 2026 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lycheeorg.
Media articles that mention a CVE ID that affects a product developed by Lycheeorg — matched by CVE ID, not by vendor name.