Skip to content
Noroxi

wallosapp records

16 published records for vendor wallosapp.

All records

16 records
  • Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by

    CriticalCVSS 9.8No exploitEPSS 1%

    wallosapp · wallosApr 16, 2025

  • Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uplo

    CriticalCVSS 9.8No exploitEPSS 1%

    wallosapp · wallosApr 16, 2025

  • Wallos: Server-Side Request Forgery (SSRF) in Notification Testers

    HighCVSS 8.8No exploitEPSS 1%

    wallosapp · wallosMar 7, 2026

  • Wallos: SSRF via url parameter leading to File Traversal

    HighCVSS 8.7No exploitEPSS 1%

    wallosapp · wallosMar 7, 2026

  • Wallos: SSRF via HTTP Proxy Environment Variable

    HighCVSS 8.3No exploitEPSS 1%

    wallosapp · wallosMar 24, 2026

  • Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

    HighCVSS 8.1No exploitEPSS 1%

    wallosapp · wallosApr 30, 2024

  • Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch

    HighCVSS 7.7No exploitEPSS 0%

    wallosapp · wallosFeb 21, 2026

  • Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840

    HighCVSS 7.7No exploitEPSS 0%

    wallosapp · wallosMar 24, 2026

  • Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php

    HighCVSS 7.1No exploitEPSS 0%

    wallosapp · wallosMar 24, 2026

  • Wallos: Password Reset Tokens Never Expire

    HighCVSS 7.1No exploitEPSS 0%

    wallosapp · wallosMar 24, 2026

  • Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php

    MediumCVSS 6.9No exploitEPSS 0%

    wallosapp · wallosMar 7, 2026

  • Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.

    MediumCVSS 6.1No exploitEPSS 0%

    wallosapp · wallosJan 23, 2025

  • Wallos: SSRF via webhook test endpoint

    MediumCVSS 5.3No exploitEPSS 0%

    wallosapp · wallosMar 7, 2026

  • Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint

    MediumCVSS 5.4No exploitEPSS 0%

    wallosapp · wallosMar 24, 2026

  • Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring s

    MediumCVSS 4.7No exploitEPSS 0%

    wallosapp · wallosFeb 23, 2024

  • Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars

    MediumCVSS 4.3No exploitEPSS 0%

    wallosapp · wallosMar 7, 2026