Wallos
Wallosapp · 16 CVEs
Wallos: Password Reset Tokens Never Expire
Mar 24, 2026
Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php
Mar 24, 2026
Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint
Mar 24, 2026
Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840
Mar 24, 2026
Wallos: SSRF via HTTP Proxy Environment Variable
Mar 24, 2026
Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars
Mar 7, 2026
Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php
Mar 7, 2026
Wallos: Server-Side Request Forgery (SSRF) in Notification Testers
Mar 7, 2026
Wallos: SSRF via webhook test endpoint
Mar 7, 2026
Wallos: SSRF via url parameter leading to File Traversal
Mar 7, 2026
Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch
Feb 21, 2026
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to…
Apr 16, 2025
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to re…
Apr 16, 2025
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profil…
Jan 23, 2025
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
Apr 30, 2024
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, exclud…
Feb 23, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-33417 | Wallos: Password Reset Tokens Never Expire | HIGH | 0.31% | Mar 24, 2026 |
| CVE-2026-33401 | Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php | HIGH | 0.41% | Mar 24, 2026 |
| CVE-2026-33400 | Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint | MEDIUM | 0.29% | Mar 24, 2026 |
| CVE-2026-33399 | Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840 | HIGH | 0.40% | Mar 24, 2026 |
| CVE-2026-33407 | Wallos: SSRF via HTTP Proxy Environment Variable | HIGH | 0.53% | Mar 24, 2026 |
| CVE-2026-30842 | Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30841 | Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php | MEDIUM | 0.35% | Mar 7, 2026 |
| CVE-2026-30840 | Wallos: Server-Side Request Forgery (SSRF) in Notification Testers | HIGH | 0.56% | Mar 7, 2026 |
| CVE-2026-30839 | Wallos: SSRF via webhook test endpoint | MEDIUM | 0.39% | Mar 7, 2026 |
| CVE-2026-30828 | Wallos: SSRF via url parameter leading to File Traversal | HIGH | 0.53% | Mar 7, 2026 |
| CVE-2026-27479 | Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch | HIGH | 0.43% | Feb 21, 2026 |
| CVE-2024-55372 | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP fil… | CRITICAL | 0.64% | Apr 16, 2025 |
| CVE-2024-55371 | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. T… | CRITICAL | 0.62% | Apr 16, 2025 |
| CVE-2024-57386 | Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function. | MEDIUM | 0.45% | Jan 23, 2025 |
| CVE-2024-29320 | Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. | HIGH | 0.67% | Apr 30, 2024 |
| CVE-2024-22776 | Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats lik… | MEDIUM | 0.47% | Feb 23, 2024 |
Showing 1 to 16 of 16 CVEs