Skip to main content

Vendor archive

lichess CVEs

Beta · best-effort

3 CVEs tagged to vendor lichess0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2026-35208

Published Apr 6, 2026

lichess.org is the forever free, adless and open source chess server. Any approved streamer can inject arbitrary HTML into /streamer and the homepage “Live streams” widget by plac…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
20.4
Vendor/product tagsBeta · best-effort

CVE-2025-52186

Published Nov 13, 2025

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players pa…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48051

Published May 15, 2025

powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1