Skip to main content

Vendor/product archive

lylme / lylme_spage CVEs

Beta · best-effort

12 CVEs tagged to lylme / lylme_spage7 Critical, 0 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2025-4543

Published May 11, 2025

A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the file lylme_spage/blob/master/admin/ajax_link.php. The manipula…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-48176

Published Nov 5, 2024

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed log…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-48357

Published Oct 28, 2024

LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-9790

Published Oct 10, 2024

A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9789

Published Oct 10, 2024

A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argumen…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-9788

Published Oct 10, 2024

A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the argumen…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-36675

Published Jun 4, 2024

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-36674

Published Jun 3, 2024

LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-34982

Published May 17, 2024

An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45952

Published Oct 17, 2023

An arbitrary file upload vulnerability in the component ajax_link.php of lylme_spage v1.7.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-45951

Published Oct 17, 2023

lylme_spage v1.7.0 was discovered to contain a SQL injection vulnerability via the $userip parameter at function.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1