ech0 records
3 published records for vendor ech0.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
30Monitor | CVE-2026-35036No exploit | Ech0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Featureech0 · ech0 · CWE-918 | High7.5 | — | 0.4% | Apr 6, 2026 |
28Monitor | CVE-2026-35037Proof of concept | Ech0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadataech0 · ech0 · CWE-918 | High7.2 | — | 0.7% | Apr 6, 2026 |
21Monitor | CVE-2026-33638No exploit | Ech0 authenticated user-list exposed data via public `/api/allusers` endpointech0 · ech0 · CWE-862 | Medium5.3 | — | 0.6% | Mar 26, 2026 |
- CVE-2026-3503630Monitor
Ech0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Feature
HighCVSS 7.5No exploitEPSS 0%ech0 · ech0Apr 6, 2026
- CVE-2026-3503728Monitor
Ech0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata
HighCVSS 7.2Proof of conceptEPSS 1%ech0 · ech0Apr 6, 2026
- CVE-2026-3363821Monitor
Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint
MediumCVSS 5.3No exploitEPSS 1%ech0 · ech0Mar 26, 2026