/Vulnerability Library

parisneo/lollms < 2.2.0 - Authenticated Stored XSS

CVE-2026-1115
Verified

Description

parisneo/lollms < 2.2.0 contains a stored XSS caused by unsanitized user input in create_post function in backend/routers/social/__init__.py, letting attackers inject malicious scripts executed in user browsers, exploit requires crafted post submission.

Severity

High

CVSS Score

9

Exploit Probability

1%

Affected Product

lollms

Published Date

August 11, 2026

Template Author

str4k3r

CVE-2026-1115.yaml
9.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-1115
CWE ID:
cwe-79

References

https://github.com/parisneo/lollms/commit/9767b882dbc893c388a286856beeaead69b8292ahttps://huntr.com/bounties/099aa4fe-7165-4337-889c-3fb4f1aa71aahttps://nvd.nist.gov/vuln/detail/CVE-2026-1115

Remediation Steps

Update to version 2.2.0 or later.