CVE-2024-48176: Lylme Spage

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Lylme Spage v1.9.5 is vulnerable to Incorrect Access Control. There is no limit on the number of login attempts, and the verification code will not be refreshed after a failed login, which allows attackers to blast the username and password and log into the system backend.

Affected products

  • Lylme Lylme Spage: version 1.9.5 only

Published 2024-11-05. Last modified 2026-06-17.