Skip to content
Noroxi

LycheeOrg records

9 published records for vendor lycheeorg.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
22.2%
Median publish → KEV
No record has entered KEV

All records

9 records
  • Lychee is vulnerable to an SQL Injection in explain DB queries.

    CriticalCVSS 9.8No exploitEPSS 0%

    lycheeorg · lycheeDec 28, 2023

  • Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create ne

    HighCVSS 8.3No exploitEPSS 0%

    lycheeorg · lycheeMar 22, 2024

  • Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php.

    MediumCVSS 6.1No exploitEPSS 1%

    lycheeorg · lycheeDec 15, 2021

  • Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information

    MediumCVSS 6.1No exploitEPSS 0%

    lycheeorg · lycheeMar 21, 2024

  • Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked

    MediumCVSS 5.3No exploitEPSS 0%

    lycheeorg · lycheeMar 26, 2026

  • Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)

    MediumCVSS 4.8No exploitEPSS 0%

    lycheeorg · lycheeMar 26, 2026

  • Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users

    LowCVSS 2.3No exploitEPSS 0%

    lycheeorg · lycheeApr 9, 2026

  • Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs

    LowCVSS 2.3No exploitEPSS 0%

    lycheeorg · lycheeMar 26, 2026

  • Lychee cross-album password propagation on Album unlocking

    LowCVSS 2.3No exploitEPSS 0%

    lycheeorg · lycheeJan 12, 2026