wallosapp records
16 published records for vendor wallosapp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 68.8%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-73 External Control of File Name or Path2
- CWE-613 Insufficient Session Expiration1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-862 Missing Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-55372No exploit | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by wallosapp · wallos · CWE-73 | Critical9.8 | — | 0.6% | Apr 16, 2025 |
39Monitor | CVE-2024-55371No exploit | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uplowallosapp · wallos · CWE-73 | Critical9.8 | — | 0.6% | Apr 16, 2025 |
35Monitor | CVE-2026-30840No exploit | Wallos: Server-Side Request Forgery (SSRF) in Notification Testerswallosapp · wallos · CWE-295 | High8.8 | — | 0.5% | Mar 7, 2026 |
34Monitor | CVE-2026-30828No exploit | Wallos: SSRF via url parameter leading to File Traversalwallosapp · wallos · CWE-22 | High8.7 | — | 0.5% | Mar 7, 2026 |
33Monitor | CVE-2026-33407No exploit | Wallos: SSRF via HTTP Proxy Environment Variablewallosapp · wallos · CWE-918 | High8.3 | — | 0.5% | Mar 24, 2026 |
32Monitor | CVE-2024-29320No exploit | Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.wallosapp · wallos · CWE-89 | High8.1 | — | 0.7% | Apr 30, 2024 |
30Monitor | CVE-2026-27479No exploit | Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetchwallosapp · wallos · CWE-918 | High7.7 | — | 0.4% | Feb 21, 2026 |
30Monitor | CVE-2026-33399No exploit | Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840wallosapp · wallos · CWE-918 | High7.7 | — | 0.4% | Mar 24, 2026 |
28Monitor | CVE-2026-33401No exploit | Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.phpwallosapp · wallos · CWE-918 | High7.1 | — | 0.4% | Mar 24, 2026 |
28Monitor | CVE-2026-33417No exploit | Wallos: Password Reset Tokens Never Expirewallosapp · wallos · CWE-613 | High7.1 | — | 0.3% | Mar 24, 2026 |
27Monitor | CVE-2026-30841No exploit | Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.phpwallosapp · wallos · CWE-79 | Medium6.9 | — | 0.3% | Mar 7, 2026 |
24Monitor | CVE-2024-57386No exploit | Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.wallosapp · wallos · CWE-79 | Medium6.1 | — | 0.5% | Jan 23, 2025 |
21Monitor | CVE-2026-30839No exploit | Wallos: SSRF via webhook test endpointwallosapp · wallos · CWE-918 | Medium5.3 | — | 0.4% | Mar 7, 2026 |
21Monitor | CVE-2026-33400No exploit | Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpointwallosapp · wallos · CWE-79 | Medium5.4 | — | 0.3% | Mar 24, 2026 |
18Monitor | CVE-2024-22776No exploit | Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring swallosapp · wallos · CWE-79 | Medium4.7 | — | 0.5% | Feb 23, 2024 |
17Monitor | CVE-2026-30842No exploit | Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatarswallosapp · wallos · CWE-862 | Medium4.3 | — | 0.3% | Mar 7, 2026 |
- CVE-2024-5537239Monitor
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by
CriticalCVSS 9.8No exploitEPSS 1%wallosapp · wallosApr 16, 2025
- CVE-2024-5537139Monitor
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uplo
CriticalCVSS 9.8No exploitEPSS 1%wallosapp · wallosApr 16, 2025
- CVE-2026-3084035Monitor
Wallos: Server-Side Request Forgery (SSRF) in Notification Testers
HighCVSS 8.8No exploitEPSS 1%wallosapp · wallosMar 7, 2026
- CVE-2026-3082834Monitor
Wallos: SSRF via url parameter leading to File Traversal
HighCVSS 8.7No exploitEPSS 1%wallosapp · wallosMar 7, 2026
- CVE-2026-3340733Monitor
Wallos: SSRF via HTTP Proxy Environment Variable
HighCVSS 8.3No exploitEPSS 1%wallosapp · wallosMar 24, 2026
- CVE-2024-2932032Monitor
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
HighCVSS 8.1No exploitEPSS 1%wallosapp · wallosApr 30, 2024
- CVE-2026-2747930Monitor
Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch
HighCVSS 7.7No exploitEPSS 0%wallosapp · wallosFeb 21, 2026
- CVE-2026-3339930Monitor
Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840
HighCVSS 7.7No exploitEPSS 0%wallosapp · wallosMar 24, 2026
- CVE-2026-3340128Monitor
Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php
HighCVSS 7.1No exploitEPSS 0%wallosapp · wallosMar 24, 2026
- CVE-2026-3341728Monitor
Wallos: Password Reset Tokens Never Expire
HighCVSS 7.1No exploitEPSS 0%wallosapp · wallosMar 24, 2026
- CVE-2026-3084127Monitor
Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php
MediumCVSS 6.9No exploitEPSS 0%wallosapp · wallosMar 7, 2026
- CVE-2024-5738624Monitor
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.
MediumCVSS 6.1No exploitEPSS 0%wallosapp · wallosJan 23, 2025
- CVE-2026-3083921Monitor
Wallos: SSRF via webhook test endpoint
MediumCVSS 5.3No exploitEPSS 0%wallosapp · wallosMar 7, 2026
- CVE-2026-3340021Monitor
Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint
MediumCVSS 5.4No exploitEPSS 0%wallosapp · wallosMar 24, 2026
- CVE-2024-2277618Monitor
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring s
MediumCVSS 4.7No exploitEPSS 0%wallosapp · wallosFeb 23, 2024
- CVE-2026-3084217Monitor
Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars
MediumCVSS 4.3No exploitEPSS 0%wallosapp · wallosMar 7, 2026