CVE-2025-4543
- EPSS 0.14%
- Veröffentlicht 11.05.2025 18:15:31
- Zuletzt bearbeitet 28.05.2025 15:46:01
A vulnerability, which was classified as critical, was found in LyLme Spage 2.1. This affects an unknown part of the file lylme_spage/blob/master/admin/ajax_link.php. The manipulation of the argument sort leads to sql injection. It is possible to ini...
CVE-2024-48176
- EPSS 0.27%
- Veröffentlicht 05.11.2024 23:15:04
- Zuletzt bearbeitet 01.05.2025 15:00:20
Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log i...
CVE-2024-48356
- EPSS 0.21%
- Veröffentlicht 28.10.2024 21:15:09
- Zuletzt bearbeitet 22.04.2025 20:24:36
LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.
CVE-2024-48357
- EPSS 0.09%
- Veröffentlicht 28.10.2024 20:15:06
- Zuletzt bearbeitet 28.04.2025 17:37:34
LyLme Spage 1.2.0 through 1.6.0 is vulnerable to SQL Injection via /admin/apply.php.
CVE-2024-9790
- EPSS 0.17%
- Veröffentlicht 10.10.2024 15:15:15
- Zuletzt bearbeitet 17.10.2024 14:26:30
A vulnerability was found in LyLme_spage 1.9.5. It has been classified as critical. Affected is an unknown function of the file /admin/sou.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. ...
CVE-2024-9788
- EPSS 0.17%
- Veröffentlicht 10.10.2024 14:15:06
- Zuletzt bearbeitet 17.10.2024 14:26:12
A vulnerability has been found in LyLme_spage 1.9.5 and classified as critical. This vulnerability affects unknown code of the file /admin/tag.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The ...
CVE-2024-9789
- EPSS 0.17%
- Veröffentlicht 10.10.2024 14:15:06
- Zuletzt bearbeitet 17.10.2024 14:26:19
A vulnerability was found in LyLme_spage 1.9.5 and classified as critical. This issue affects some unknown processing of the file /admin/apply.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The ...
CVE-2024-36675
- EPSS 44.28%
- Veröffentlicht 04.06.2024 22:15:10
- Zuletzt bearbeitet 21.11.2024 09:22:30
LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.
CVE-2024-36674
- EPSS 0.15%
- Veröffentlicht 03.06.2024 16:15:08
- Zuletzt bearbeitet 17.06.2025 19:56:44
LyLme_spage v1.9.5 is vulnerable to Cross Site Scripting (XSS) via admin/link.php.
CVE-2024-34982
- EPSS 78.35%
- Veröffentlicht 17.05.2024 14:15:11
- Zuletzt bearbeitet 17.06.2025 19:57:04
An arbitrary file upload vulnerability in the component /include/file.php of lylme_spage v1.9.5 allows attackers to execute arbitrary code via uploading a crafted file.