CVE-2026-1115Disclosure(lollms / lollms)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch lollms lollms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned to the `DBPost` model without sanitization. This allows attackers to inject and store malicious JavaScript, which is executed in the browsers of users viewing the Home Feed, including administrators. This can lead to account takeover, session hijacking, and wormable attacks. The issue is resolved in version 2.2.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • lollms

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 4 mentions (2026-04-10); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
lollms

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 2Mentions · 2026-08-17: 1Patch / Workaround · 2026-04-10: 2Technical Details · 2026-04-10: 4Technical Details · 2026-04-11: 2Technical Details · 2026-08-17: 104-1004-1108-17
Signal classification2 categories
Disclosure
571.4%
Patch
228.6%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure2Patch2
2026-04-112
Disclosure2
2026-08-171
Disclosure1
Full discourse7 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1115 - high 🚨 parisneo/lollms < 2.2.0 - Authenticated Stored XSS > parisneo/lollms < 2.2.0 contains a stored XSS caused by unsanitized user input in cre... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1115 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet discloses CVE-2026-1115, a high‑severity authenticated stored XSS in parisneo/lollms versions earlier than 2.2.0 caused by unsanitized input, but provides no patches, PoC, or evidence of active exploitation.

    01092660
    1.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1115 A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-1115

    Post summary

    The post announces a stored XSS flaw in parisneo/lollms before version 2.2.0, providing basic technical details but no PoC, active exploitation, or patch information.

    0001093
    57.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-1115 📊 Severity: 9.6 🚨 Risk Level: Critical 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-1115 #CVE-2026-1115 #CVE #Critical #CyberSecurity #InfoSec https://t.co/hmSufLySev

    Post summary

    The tweet announces CVE‑2026‑1115, highlighting its 9.6 severity score and critical risk level, but provides no PoC, exploit, patch, or active exploitation details.

    0000037
    125 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A stored #XSS vulnerability (CVE-2026-1115) impacts the social feature of `ParisNeo Lollms`. Malicious scripts can execute in other users' browsers. Monitor for fixes. #Lollms #Infosec https://www.pulsepatch.io/posts/cve-2026-1115-parisneo-lollms-stored-xss

    Post summary

    The post announces a stored XSS flaw (CVE‑2026‑1115) in ParisNeo Lollms’ social feature, noting that malicious scripts can run in other users’ browsers and urges users to watch for forthcoming fixes.

    0000053
    11 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-1115: CRITICAL] Stored XSS vulnerability in Paris Neo Lollms social feature prior to version 2.2.0 can lead to malicious JavaScript injection - update to 2.2.0 to fix the issue.#cve,CVE-2026-1115,#cybersecurity https://cvefind.com/CVE-2026-1115

    Post summary

    The tweet discloses a critical stored XSS vulnerability (CVE-2026-1115) in Paris Neo Lollms and advises updating to v2.2.0 to mitigate the flaw.

    0000034
    619 followersView on X
  • Giuseppe Paternicola@giuseppe_1337
    Patch

    ```json { "x": "🚨 CRITICAL: CVE-2026-1115 (CVSS 9.6) - Stored XSS in parisneo/lollms <2.2.0. Attackers inject malicious JS via social posts → account takeover, session hijacking, wormable attacks. Upgrade to 2.2.0 immediately. https://t.co/FIKVzQ4i2g

    Post summary

    A critical Stored XSS flaw (CVE-2026-1115) affecting parisneo/lollms versions below 2.2.0 is disclosed with a strong recommendation to upgrade to 2.2.0 immediately.

    0000028
    6 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-1115: Stored XSS in parisneo/lollms (CV... LOLLMS social feed drops unsanitized user content straight into DBPost model - trivial wormable XSS with admin session h... https://zerodaysignal.com/vulnerability/CVE-2026-1115 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-1115 is a stored XSS vulnerability in Lollms that allows trivial wormable XSS via admin sessions; no PoC, exploit code, active exploitation evidence, or patch details are provided.

    0000055
    204 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applollmslollms---

Explore more