Lylme's vulnerability footprint centers on a single web-based document-sharing product, Spage, that sits at a moderate level of prominence in the landscape. The vendor's disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code, driven by recurring application-layer input-handling weaknesses—SQL injection, cross-site scripting, unrestricted file upload, and related injection flaws—alongside authorization bypass conditions that are common in web platforms lacking mature input-validation and access-control architecture. Defenders treating this vendor should monitor patches and treat exposed instances as high-priority given the severity tendency and exploit availability; live exploitation status and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lylme over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-34982CRITICAL An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file. | May 17, 2024 | 9.8 | 39 | NO | YES |
CVE-2024-36675CRITICAL LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function. | Jun 4, 2024 | 9.1 | 35 | NO | YES |
CVE-2023-45951CRITICAL lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php. | Oct 17, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-48176CRITICAL Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed logi | Nov 5, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-45952CRITICAL An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file. | Oct 17, 2023 | 9.8 | 26 | NO | NO |
CVE-2024-48356CRITICAL LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php. | Oct 28, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-48357CRITICAL LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php. | Oct 28, 2024 | 9.8 | 25 | NO | NO |
CVE-2024-9790HIGH A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id | Oct 10, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-9789HIGH A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argument | Oct 10, 2024 | 7.2 | 21 | NO | NO |
CVE-2024-9788HIGH A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the argument | Oct 10, 2024 | 7.2 | 21 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lylme.
Media articles that mention a CVE ID that affects a product developed by Lylme — matched by CVE ID, not by vendor name.