Wallos

Ellite · 27 CVEs

CVE-2026-77353
MEDIUM

Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export

Aug 31, 2026

CVE-2026-77352
MEDIUM

Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)

Aug 31, 2026

CVE-2026-77348
HIGH

Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.p…

Aug 31, 2026

CVE-2026-77351
LOW

Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings

Aug 31, 2026

CVE-2026-61641
HIGH

Wallos: OIDC account takeover via email-based account linking without `email_verified` check

Aug 31, 2026

CVE-2026-61640
HIGH

Wallos: SSRF via OIDC Token/UserInfo URL Configuration

Aug 31, 2026

CVE-2026-61639
HIGH

Wallos: Zip Slip path traversal in database restore writes files to webroot

Aug 31, 2026

CVE-2026-61638
HIGH

Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port

Aug 31, 2026

CVE-2026-54600
HIGH

Wallos: Unauthenticated database replacement via import endpoint on fresh install

Aug 31, 2026

CVE-2026-54599
HIGH

Wallos: OIDC state parameter never validated — login CSRF / account takeover

Aug 31, 2026

CVE-2026-54598
HIGH

Missing Authentication for Critical Function in wallos

Aug 31, 2026

CVE-2026-50199
MEDIUM

Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh

Aug 31, 2026

CVE-2026-50198
MEDIUM

Wallos: Cross-user subscription cost inference via replacement_subscription_id

Aug 31, 2026

CVE-2026-41689
MEDIUM

Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services

May 7, 2026

CVE-2026-41688
HIGH

Incomplete fix for CVE-2026-33399: SSRF in Wallos

May 7, 2026

CVE-2026-41687
MEDIUM

Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks

May 7, 2026

CVE-2026-33417
HIGH

Wallos: Password Reset Tokens Never Expire

Mar 24, 2026

CVE-2026-33401
HIGH

Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php

Mar 24, 2026

CVE-2026-33400
MEDIUM

Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint

Mar 24, 2026

CVE-2026-33399
HIGH

Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840

Mar 24, 2026

CVE-2026-33407
HIGH

Wallos: SSRF via HTTP Proxy Environment Variable

Mar 24, 2026

CVE-2026-30842
MEDIUM

Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars

Mar 7, 2026

CVE-2026-30841
MEDIUM

Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php

Mar 7, 2026

CVE-2026-30840
HIGH

Wallos: Server-Side Request Forgery (SSRF) in Notification Testers

Mar 7, 2026

CVE-2026-30839
MEDIUM

Wallos: SSRF via webhook test endpoint

Mar 7, 2026

Showing 1 to 25 of 27 CVEs