LycheeOrg kayıtları
lycheeorg üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %22,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-863 Incorrect Authorization2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-52082İstismar yok | Lychee is vulnerable to an SQL Injection in explain DB queries.lycheeorg · lychee · CWE-89 | Kritik9,8 | — | %0,5 | 28 Ara 2023 |
33İzleyin | CVE-2024-25808İstismar yok | Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create nelycheeorg · lychee · CWE-352 | Yüksek8,3 | — | %0,4 | 22 Mar 2024 |
24İzleyin | CVE-2021-43675İstismar yok | Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php.lycheeorg · lychee · CWE-79 | Orta6,1 | — | %0,9 | 15 Ara 2021 |
24İzleyin | CVE-2024-25807İstismar yok | Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive informationlycheeorg · lychee · CWE-79 | Orta6,1 | — | %0,5 | 21 Mar 2024 |
21İzleyin | CVE-2026-33537İstismar yok | Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blockedlycheeorg · lychee · CWE-918 | Orta5,3 | — | %0,3 | 26 Mar 2026 |
19İzleyin | CVE-2026-33738İstismar yok | Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)lycheeorg · lychee · CWE-79 | Orta4,8 | — | %0,4 | 26 Mar 2026 |
9İzleyin | CVE-2026-39957İstismar yok | Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized userslycheeorg · lychee · CWE-863 | Düşük2,3 | — | %0,3 | 9 Nis 2026 |
9İzleyin | CVE-2026-33644İstismar yok | Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPslycheeorg · lychee · CWE-918 | Düşük2,3 | — | %0,3 | 26 Mar 2026 |
9İzleyin | CVE-2026-22784İstismar yok | Lychee cross-album password propagation on Album unlockinglycheeorg · lychee · CWE-863 | Düşük2,3 | — | %0,3 | 12 Oca 2026 |
- CVE-2023-5208239İzleyin
Lychee is vulnerable to an SQL Injection in explain DB queries.
KritikCVSS 9,8İstismar yokEPSS %0lycheeorg · lychee28 Ara 2023
- CVE-2024-2580833İzleyin
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create ne
YüksekCVSS 8,3İstismar yokEPSS %0lycheeorg · lychee22 Mar 2024
- CVE-2021-4367524İzleyin
Lychee-v3 3.2.16 is affected by a Cross Site Scripting (XSS) vulnerability in php/Access/Guest.php.
OrtaCVSS 6,1İstismar yokEPSS %1lycheeorg · lychee15 Ara 2021
- CVE-2024-2580724İzleyin
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information
OrtaCVSS 6,1İstismar yokEPSS %0lycheeorg · lychee21 Mar 2024
- CVE-2026-3353721İzleyin
Lychee has SSRF bypass via incomplete IP validation in Photo::fromUrl — loopback and link-local IPs not blocked
OrtaCVSS 5,3İstismar yokEPSS %0lycheeorg · lychee26 Mar 2026
- CVE-2026-3373819İzleyin
Lychee Vulnerable to Stored XSS via Photo Description in RSS/Atom/JSON Feed (No Sanitization on Public Endpoint)
OrtaCVSS 4,8İstismar yokEPSS %0lycheeorg · lychee26 Mar 2026
- CVE-2026-399579İzleyin
Lychee has Broken Access Control in SharingController::listAll() leaks private album sharing metadata to unauthorized users
DüşükCVSS 2,3İstismar yokEPSS %0lycheeorg · lychee9 Nis 2026
- CVE-2026-336449İzleyin
Lychee has SSRF bypass via DNS rebinding — PhotoUrlRule only validates IP addresses, not hostnames resolving to internal IPs
DüşükCVSS 2,3İstismar yokEPSS %0lycheeorg · lychee26 Mar 2026
- CVE-2026-227849İzleyin
Lychee cross-album password propagation on Album unlocking
DüşükCVSS 2,3İstismar yokEPSS %0lycheeorg · lychee12 Oca 2026