Giuseppe Paternicola[verified]@giuseppe_1337Patch
A critical Stored XSS flaw (CVE-2026-1115) affecting parisneo/lollms versions below 2.2.0 is disclosed with a strong recommendation to upgrade to 2.2.0 immediately.
pdnuclei-bot@pdnuclei_botDisclosure
The tweet discloses CVE-2026-1115, a high‑severity authenticated stored XSS in parisneo/lollms versions earlier than 2.2.0 caused by unsanitized input, but provides no patches, PoC, or evidence of active exploitation.
CVE@CVEnewDisclosure
The post announces a stored XSS flaw in parisneo/lollms before version 2.2.0, providing basic technical details but no PoC, active exploitation, or patch information.
CVEarity@CVEarityDisclosure
The tweet announces CVE‑2026‑1115, highlighting its 9.6 severity score and critical risk level, but provides no PoC, exploit, patch, or active exploitation details.
PulsePatch.io@pulsepatchioDisclosure
The post announces a stored XSS flaw (CVE‑2026‑1115) in ParisNeo Lollms’ social feature, noting that malicious scripts can run in other users’ browsers and urges users to watch for forthcoming fixes.
CVEFind.com@CveFindComPatch
The tweet discloses a critical stored XSS vulnerability (CVE-2026-1115) in Paris Neo Lollms and advises updating to v2.2.0 to mitigate the flaw.
0day Signal@0dayPublishingDisclosure
CVE-2026-1115 is a stored XSS vulnerability in Lollms that allows trivial wormable XSS via admin sessions; no PoC, exploit code, active exploitation evidence, or patch details are provided.