Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Halo HIGH 7.5
CVE-2025-70886

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission end…

Fix: after 2.22.4
Fix from $1,950 2026-02-12
Halo MEDIUM 6.1
CVE-2025-44593

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can …

Fix: 2.20.13+
Fix from $1,600 2025-09-09
Halo MEDIUM 6.1
CVE-2025-44595

Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.

Fix: after 2.20.17
Fix from $1,600 2025-09-09
Halo CRITICAL 9.1
CVE-2025-44594

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

Fix: after 2.20.17
Fix from $2,300 2025-09-09
Halo CRITICAL 9.0
CVE-2024-56156

Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation contr…

Fix: 2.20.13+
Fix from $2,300 2025-04-25
Halo MEDIUM 6.4
CVE-2024-43793

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vuln…

Fix: 2.19.0+
Fix from $1,600 2024-09-11
Halo MEDIUM 6.1
CVE-2024-43792

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vuln…

Fix: 2.17.0+
Fix from $1,600 2024-09-02
Halo MEDIUM 6.1
CVE-2023-33528

halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2024-03-28
Halo CRITICAL 9.8
CVE-2022-32994EPSS 17%

Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.

No fix yet
Fix from $2,300 2022-06-27
Halo CRITICAL 9.8
CVE-2022-32995EPSS 16%

Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.

No fix yet
Fix from $2,300 2022-06-27
Halo HIGH 7.5
CVE-2022-26619

Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

No fix yet
Fix from $1,950 2022-04-05
Halo MEDIUM 5.4
CVE-2021-43659

In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS v…

No fix yet
Fix from $1,600 2022-03-24
Halo CRITICAL 9.1
CVE-2020-19038

File Deletion vulnerability in Halo 0.4.3 via delBackup.

No fix yet
Fix from $2,300 2021-07-12
Halo HIGH 7.5
CVE-2020-23079

SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.

Fix: after 1.3.2
Fix from $1,950 2021-07-12
Halo MEDIUM 5.4
CVE-2020-18982

Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.

No fix yet
Fix from $1,600 2021-07-12
Halo MEDIUM 5.3
CVE-2020-19037

Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.

No fix yet
Fix from $1,600 2021-07-12
Halo CRITICAL 9.8
CVE-2020-18980

Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.

No fix yet
Fix from $2,300 2021-07-12
Halo MEDIUM 6.1
CVE-2020-18979

Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.

No fix yet
Fix from $1,600 2021-07-12
Halo MEDIUM 6.1
CVE-2020-21345

Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute ar…

No fix yet
Fix from $1,600 2021-05-20
Halo CRITICAL 9.8
CVE-2020-21526

An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on…

No fix yet
Fix from $2,300 2020-09-30
Halo CRITICAL 9.1
CVE-2020-21524

There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/word…

No fix yet
Fix from $2,300 2020-09-30
Halo HIGH 7.7
CVE-2020-21527

There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files…

Mitigation only
Fix from $1,950 2020-09-30
Halo HIGH 7.5
CVE-2020-21525

Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the …

No fix yet
Fix from $1,950 2020-09-30
Halo CRITICAL 9.8
CVE-2020-21522

An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ft…

No fix yet
Fix from $2,300 2020-09-30
Halo CRITICAL 9.8
CVE-2020-21523

A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the…

No fix yet
Fix from $2,300 2020-09-30
Halo MEDIUM 5.4
CVE-2020-19007

Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then…

No fix yet
Fix from $1,600 2020-08-26
Halo HIGH 7.2
CVE-2019-19999

Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker conf…

Fix: after 1.1.1
Fix from $1,950 2019-12-26
Halo MEDIUM 5.4
CVE-2019-16890

Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.

Patch available
Fix from $1,600 2019-09-25
Halo MEDIUM 6.1
CVE-2018-11011

ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.

No fix yet
Fix from $1,600 2018-05-12
Halo MEDIUM 6.1
CVE-2018-11012

ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.

No fix yet
Fix from $1,600 2018-05-12