Wallos
Ellite · 27 CVEs
Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export
Aug 31, 2026
Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)
Aug 31, 2026
Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.p…
Aug 31, 2026
Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings
Aug 31, 2026
Wallos: OIDC account takeover via email-based account linking without `email_verified` check
Aug 31, 2026
Wallos: SSRF via OIDC Token/UserInfo URL Configuration
Aug 31, 2026
Wallos: Zip Slip path traversal in database restore writes files to webroot
Aug 31, 2026
Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port
Aug 31, 2026
Wallos: Unauthenticated database replacement via import endpoint on fresh install
Aug 31, 2026
Wallos: OIDC state parameter never validated — login CSRF / account takeover
Aug 31, 2026
Missing Authentication for Critical Function in wallos
Aug 31, 2026
Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh
Aug 31, 2026
Wallos: Cross-user subscription cost inference via replacement_subscription_id
Aug 31, 2026
Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services
May 7, 2026
Incomplete fix for CVE-2026-33399: SSRF in Wallos
May 7, 2026
Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks
May 7, 2026
Wallos: Password Reset Tokens Never Expire
Mar 24, 2026
Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php
Mar 24, 2026
Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint
Mar 24, 2026
Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840
Mar 24, 2026
Wallos: SSRF via HTTP Proxy Environment Variable
Mar 24, 2026
Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars
Mar 7, 2026
Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php
Mar 7, 2026
Wallos: Server-Side Request Forgery (SSRF) in Notification Testers
Mar 7, 2026
Wallos: SSRF via webhook test endpoint
Mar 7, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-77353 | Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export | MEDIUM | 0.29% | Aug 31, 2026 |
| CVE-2026-77352 | Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) | MEDIUM | 0.33% | Aug 31, 2026 |
| CVE-2026-77348 | Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php` | HIGH | 0.43% | Aug 31, 2026 |
| CVE-2026-77351 | Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings | LOW | 0.29% | Aug 31, 2026 |
| CVE-2026-61641 | Wallos: OIDC account takeover via email-based account linking without `email_verified` check | HIGH | 0.53% | Aug 31, 2026 |
| CVE-2026-61640 | Wallos: SSRF via OIDC Token/UserInfo URL Configuration | HIGH | 0.54% | Aug 31, 2026 |
| CVE-2026-61639 | Wallos: Zip Slip path traversal in database restore writes files to webroot | HIGH | 0.51% | Aug 31, 2026 |
| CVE-2026-61638 | Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port | HIGH | 0.50% | Aug 31, 2026 |
| CVE-2026-54600 | Wallos: Unauthenticated database replacement via import endpoint on fresh install | HIGH | 0.58% | Aug 31, 2026 |
| CVE-2026-54599 | Wallos: OIDC state parameter never validated — login CSRF / account takeover | HIGH | 0.22% | Aug 31, 2026 |
| CVE-2026-54598 | Missing Authentication for Critical Function in wallos | HIGH | 0.46% | Aug 31, 2026 |
| CVE-2026-50199 | Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh | MEDIUM | 0.26% | Aug 31, 2026 |
| CVE-2026-50198 | Wallos: Cross-user subscription cost inference via replacement_subscription_id | MEDIUM | 0.29% | Aug 31, 2026 |
| CVE-2026-41689 | Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services | MEDIUM | 0.27% | May 7, 2026 |
| CVE-2026-41688 | Incomplete fix for CVE-2026-33399: SSRF in Wallos | HIGH | 0.39% | May 7, 2026 |
| CVE-2026-41687 | Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks | MEDIUM | 0.33% | May 7, 2026 |
| CVE-2026-33417 | Wallos: Password Reset Tokens Never Expire | HIGH | 0.31% | Mar 24, 2026 |
| CVE-2026-33401 | Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php | HIGH | 0.41% | Mar 24, 2026 |
| CVE-2026-33400 | Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint | MEDIUM | 0.29% | Mar 24, 2026 |
| CVE-2026-33399 | Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840 | HIGH | 0.40% | Mar 24, 2026 |
| CVE-2026-33407 | Wallos: SSRF via HTTP Proxy Environment Variable | HIGH | 0.53% | Mar 24, 2026 |
| CVE-2026-30842 | Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30841 | Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30840 | Wallos: Server-Side Request Forgery (SSRF) in Notification Testers | HIGH | 0.56% | Mar 7, 2026 |
| CVE-2026-30839 | Wallos: SSRF via webhook test endpoint | MEDIUM | 0.39% | Mar 7, 2026 |
Showing 1 to 25 of 27 CVEs