shouldiuse.io

Categories

VERDICT

Should I use Lychee (LycheeOrg)?

A great looking and easy-to-use photo-management-system you can run on your server. - lycheeorg.github.io

Depends. Buy it if you can run and patch a server and want your photos off cloud services — it is free, open source, and actively maintained. Skip it if you want vendor support, automatic mobile backup, or zero-maintenance hosting.

Confidence

Medium. Based on ~30 public sources across GitHub, Reddit, Hacker News, and CVE databases; no named corporate users found.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Self-hosted

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes

Best for

  • Self-hosters comfortable with Docker
  • Privacy-focused personal photo libraries
  • Small groups sharing galleries on their own server
  • PHP/Laravel hobbyist admins

Not for

  • Non-technical users wanting plug-and-play photo backup
  • Businesses needing vendor SLAs or guaranteed support
  • Mobile-first users wanting automatic camera-roll sync (Guess: Immich fits better)
  • Anyone unwilling to patch promptly against CVEs

Gotchas - check before you buy

high

Several 2026 CVEs (SSRF, stored XSS) mean you must update fast.

medium

No SLA: fixes depend on volunteer maintainers with limited funding.

medium

Album-password flaw let unlocked access propagate across albums until patched January 2026.

low

Some third-party sites list misleading sponsored '$999' pricing; the real price is free.

Pros and cons

Pros

  • Free and open source under the MIT license
  • Self-hosted: photos stay on your own server
  • Actively maintained; version 7.10.0 just shipped
  • Multi-user support confirmed
  • One-command Docker deployment

Cons

  • You supply and maintain the server, database, and updates
  • 11 CVEs logged, including XSS, CSRF, and SSRF
  • Community-only support; maintainers report funding struggles
  • Frequent security releases demand prompt patching
  • Often compared against Piwigo, PhotoPrism, Immich, and Memories

Sources & method

Analyzed 9/29/2026 - 12 sources - 11 known CVEs plus GitHub advisories; project publishes and patches them, but you must run current releases.

official x4review x4security x4
  • CVE-2026-33644 — SSRF bypass via DNS, Server-side request forgery bypass disclosed March 2026.
  • CVE-2026-33738 — Stored XSS, Stored cross-site scripting via user input, disclosed March 2026.
  • CVE-2024-25808 — CSRF, Cross-site request forgery flaw in earlier versions.
  • CVE-2026-39957, Medium-severity issue, fixed in version 7.5.
  • Cross-album password propagation, Album unlocking leaked access across albums; advisory January 2026.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Free, MIT-licensed, no subscriptions.
  • Ease of use: 3/5. Easy once running; setup needs server skills.
  • Feature depth: 3/5. Albums, sharing, API; v7 added FrankenPHP and webshop.
  • Support quality: 2/5. Volunteer community only; no vendor support.
  • Security posture: 2/5. 11 CVEs; advisories published and patched promptly.
  • $0 Price MIT-licensed, donation-funded
  • MIT License Free and open source
  • 11 Known CVEs Per OpenCVE tracker
  • 7.10.0 Latest release Shown on project homepage

Pricing

Self-hosted

Free

  • Full app, MIT licensed
  • Donation-funded via OpenCollective
  • You provide server, storage, and updates

Security

11 known CVEs plus GitHub advisories; project publishes and patches them, but you must run current releases.

  • CVE-2026-33644 — SSRF bypass via DNSServer-side request forgery bypass disclosed March 2026.
  • CVE-2026-33738 — Stored XSSStored cross-site scripting via user input, disclosed March 2026.
  • CVE-2024-25808 — CSRFCross-site request forgery flaw in earlier versions.⁷
  • CVE-2026-39957Medium-severity issue, fixed in version 7.5.⁶
  • Cross-album password propagationAlbum unlocking leaked access across albums; advisory January 2026.⁸

What users say

Self-hosters weigh Lychee against Piwigo, PhotoPrism, and Immich; long-term users are loyal, but the project leans on stretched volunteer maintainers.

“I've been using Lychee for many years”
Hacker News
“LycheeOrg is the only one being currently maintained.”
Reddit, r/selfhosted
Full analysis

Based on ~30 public sources across GitHub, Reddit, Hacker News, and CVE databases; no named corporate users found.

Free, solid self-hosted photo gallery for tinkerers; wrong pick if you want managed, supported, plug-and-play photo backup.

Methodology

Based on ~30 public sources across GitHub, Reddit, Hacker News, and CVE databases; no named corporate users found.

Sources

  1. official
  2. Lychee homepagelycheeorg.github.io
    official
  3. LycheeOrg on OpenCollectiveopencollective.com
    official
  4. Lychee Docker imagehub.docker.com
    official
  5. security
  6. security
  7. security
  8. security
  9. review
  10. review
  11. review
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.