Products: 2
    Vulnerabilities: 3
    Known Exploited: 0
    0
    Critical Level Threats
    0
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-35208

    lichess.org has an Unsanitized Stream Title Injection on /streamer

    Last Modified: Apr 16, 2026
    Published: Apr 06, 2026

    CVE-2025-52186

    Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to an internal HTTP client without validation, allowing remote attackers to force the server to send HTTP requests to arbitrary URLs

    Last Modified: Jan 09, 2026
    Published: Nov 13, 2025

    CVE-2025-48051

    powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern in which text is extracted from a DOM node and interpreted as HTML.

    Last Modified: Jun 12, 2025
    Published: May 15, 2025
    Items Per Page