216.73.216.233

CVE-2026-1115

· Published 10/04/2026 07:16 · Modified 10/04/2026 13:16

Labels: CVE-2026-1115 2026-04-10CVE-2026-1115CWE-79[email protected]

Essential information

Published
10/04/2026 07:16
Modified
10/04/2026 13:16
Author
Creator
CVSS
9.6 CRITICAL (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

CVSS metrics

Description

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned to the `DBPost` model without sanitization. This allows attackers to inject and store malicious JavaScript, which is executed in the browsers of users viewing the Home Feed, including administrators. This can lead to account takeover, session hijacking, and wormable attacks. The issue is resolved in version 2.2.0.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
parisneo / lollms cpe:2.3:a:parisneo:lollms:<2.2.0:*:*:*:*:*:*:*

References