VYPR

lms

by Epoupon

CVEs (1)

  • CVE-2026-48559MedJun 1, 2026
    risk 0.35cvss 5.4epss

    Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted…