Saifeddine ALOUI
26 exploits
Active since Mar 2024
Cross-site Scripting (XSS) in parisneo/lollms
CVSS 6.1
Stored XSS in parisneo/lollms
CVSS 9.6
Improper Access Control via Weak JWT Token in parisneo/lollms
CVSS 9.8
Unauthenticated File Upload in parisneo/lollms
CVSS 9.8
Server-Side Request Forgery (SSRF) in parisneo/lollms
CVSS 7.5
Insecure Direct Object Reference (IDOR) in parisneo/lollms
CVSS 8.3
Lollms Web UI < 9.2 - OS Command Injection
CVSS 9.8
Lollms Web UI < 9.2 - CSRF
CVSS 8.8
Lollms-webui - Denial of Service
CVSS 7.5
Lollms Web UI < 9.6 - Remote File Inclusion
CVSS 9.3
Lollms-webui - SQL Injection
CVSS 9.8
Lollms-webui < 9.3 - Denial of Service
CVSS 8.2
Lollms Web UI - Path Traversal
CVSS 9.1
Lollms <7.3.0 - CSRF
CVSS 8.3
parisneo/lollms-webui - LFI
CVSS 9.6
Lollms Web UI < 9.5 - Path Traversal
CVSS 7.5
parisneo/lollms-webui - Path Traversal
CVSS 9.8
parisneo/lollms-webui - Command Injection
CVSS 8.4
Parisneo/lollms-webui <9.5 - Path Traversal
CVSS 9.8
parisneo/lollms-webui <9.3 - RCE
CVSS 9.8
parisneo/lollms-webui <9.6 - XSS/Open Redirect
CVSS 7.3
parisneo/lollms-webui <9.9 - CSRF
CVSS 6.5
parisneo/lollms-webui <10 - SSRF
CVSS 7.1
parisneo/lollms-webui V12 - Path Traversal
CVSS 9.1
Lollms Web UI - Path Traversal
CVSS 9.8