CVE-2024-48356: Lylme Spage

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

LyLme Spage <=1.6.0 is vulnerable to SQL Injection via /admin/group.php.

Affected products

  • Lylme Lylme Spage: up to and including 1.6.0

Published 2024-10-28. Last modified 2026-06-17.