S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Aug 30, 2026

CVE-2026-1115 Scanner

CVE-2026-1115 Scanner - Cross-Site Scripting (XSS) vulnerability in parisneo/lollms

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-1115
9.6
CVSScritical
Exploitable remotely over the internet · no authentication required · user interaction needed.

A Stored Cross-Site Scripting (XSS) vulnerability was identified in the social feature of parisneo/lollms, affecting the latest version prior to 2.2.0. The vulnerability exists in the `create_post` function within `backend/routers/social/__init__.py`, where user-provided content is directly assigned to the `DBPost` model without sanitization. This allows attackers to inject and store malicious JavaScript, which is executed in the browsers of users viewing the Home Feed, including administrators. This can lead to account takeover, session hijacking, and wormable attacks. The issue is resolved in version 2.2.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
parisneo/lollmsby parisneo
AFFECTED< 2.2.0SAFE ✓≥ 2.2.0
Updated Aug 22, 2026View on NVD →
Detail

The parisneo/lollms software is a widely used platform that facilitates social interactions among users. Organizations and individuals around the world utilize it for creating and sharing content with an extensive audience. Parisneo/lollms provides robust tools for managing posts and accessing social feeds, making it a preferred choice for developers and content creators. The software's flexibility allows integration with various platforms, enhancing user experiences. Moreover, the community and support around parisneo/lollms ensure continuous development and improvement.

The Cross-Site Scripting (XSS) vulnerability detected in parisneo/lollms is a common security flaw that can have serious implications. It allows attackers to inject malicious scripts into web pages viewed by other users. Such scripts can execute arbitrary actions on behalf of the logged-in user, leading to potential account takeovers or other malicious activities. This vulnerability highlights the need for adequate input sanitization and validation. Its presence underscores the importance of updating software to mitigate security risks.

Technically speaking, the vulnerability is rooted in the create_post function within the backend/routers/social/__init__.py file. Due to inadequate sanitization, user input is not properly sanitized. Attackers can craft malicious payloads that include scripts, which are then stored and executed in user browsers. Specifically, the vulnerability allows crafted post submissions to include harmful HTML or JavaScript code. This can be exploited when unsuspecting users access infected pages, leading to potential security breaches.

When exploited, this XSS vulnerability can have severe consequences. Malicious actors could take control of user accounts, leading to serious breaches of privacy. They could hijack user sessions, allowing them to navigate and act on behalf of the user. Additionally, wormable attacks may spread the vulnerability further, endangering a wider network of users. Compromised scripts can capture sensitive information or perform unauthorized actions, resulting in compromised systems and reputation damage.

REFERENCES

Solution Advice
  • Update parisneo/lollms to version 2.2.0 or later to patch the vulnerability.
  • Implement input validation and sanitization to prevent the injection of malicious scripts.
  • Conduct regular security audits to identify and mitigate potential vulnerabilities.
  • Educate developers about secure coding practices to enhance overall software security.
  • Consider deploying security tools or services to continuously monitor for and detect XSS vulnerabilities.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.