Wallos

Wallosapp · 16 CVEs

CVE-2026-33417
HIGH

Wallos: Password Reset Tokens Never Expire

Mar 24, 2026

CVE-2026-33401
HIGH

Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php

Mar 24, 2026

CVE-2026-33400
MEDIUM

Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint

Mar 24, 2026

CVE-2026-33399
HIGH

Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840

Mar 24, 2026

CVE-2026-33407
HIGH

Wallos: SSRF via HTTP Proxy Environment Variable

Mar 24, 2026

CVE-2026-30842
MEDIUM

Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars

Mar 7, 2026

CVE-2026-30841
MEDIUM

Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php

Mar 7, 2026

CVE-2026-30840
HIGH

Wallos: Server-Side Request Forgery (SSRF) in Notification Testers

Mar 7, 2026

CVE-2026-30839
MEDIUM

Wallos: SSRF via webhook test endpoint

Mar 7, 2026

CVE-2026-30828
HIGH

Wallos: SSRF via url parameter leading to File Traversal

Mar 7, 2026

CVE-2026-27479
HIGH

Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch

Feb 21, 2026

CVE-2024-55372
CRITICAL

Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to…

Apr 16, 2025

CVE-2024-55371
CRITICAL

Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to re…

Apr 16, 2025

CVE-2024-57386
MEDIUM

Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profil…

Jan 23, 2025

CVE-2024-29320
HIGH

Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

Apr 30, 2024

CVE-2024-22776
MEDIUM

Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, exclud…

Feb 23, 2024

Showing 1 to 16 of 16 CVEs