CVE-2024-36675: Lylme Spage

Critical severity, CVSS 9.1. EPSS: 1.4% chance of exploitation in the next 30 days.

LyLme_spage v1.9.5 is vulnerable to Server-Side Request Forgery (SSRF) via the get_head function.

Affected products

  • Lylme Lylme Spage: version 1.9.5 only

Published 2024-06-04. Last modified 2026-06-17.