Vulnerability index

Browse CVEs

20 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2023-33528 halo v1.6.0 is vulnerable to Cross Site Scripting (XSS). Halo No fix yet Fix from $1,6002024-03-28 CRITICAL 9.8 CVE-2022-32994EPSS 17% Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. Halo No fix yet Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-32995EPSS 16% Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. Halo No fix yet Fix from $2,3002022-06-27 HIGH 7.5 CVE-2022-26619 Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. Halo No fix yet Fix from $1,9502022-04-05 MEDIUM 5.4 CVE-2021-43659 In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS v… Halo No fix yet Fix from $1,6002022-03-24 CRITICAL 9.1 CVE-2020-19038 File Deletion vulnerability in Halo 0.4.3 via delBackup. Halo No fix yet Fix from $2,3002021-07-12 MEDIUM 5.4 CVE-2020-18982 Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl. Halo No fix yet Fix from $1,6002021-07-12 MEDIUM 5.3 CVE-2020-19037 Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies. Halo No fix yet Fix from $1,6002021-07-12 CRITICAL 9.8 CVE-2020-18980 Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters. Halo No fix yet Fix from $2,3002021-07-12 MEDIUM 6.1 CVE-2020-18979 Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter. Halo No fix yet Fix from $1,6002021-07-12 MEDIUM 6.1 CVE-2020-21345 Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute ar… Halo No fix yet Fix from $1,6002021-05-20 CRITICAL 9.8 CVE-2020-21526 An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on… Halo No fix yet Fix from $2,3002020-09-30 CRITICAL 9.1 CVE-2020-21524 There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/word… Halo No fix yet Fix from $2,3002020-09-30 HIGH 7.7 CVE-2020-21527 There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files… Halo Mitigation only Fix from $1,9502020-09-30 HIGH 7.5 CVE-2020-21525 Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the … Halo No fix yet Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-21522 An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ft… Halo No fix yet Fix from $2,3002020-09-30 CRITICAL 9.8 CVE-2020-21523 A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the… Halo No fix yet Fix from $2,3002020-09-30 MEDIUM 5.4 CVE-2020-19007 Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then… Halo No fix yet Fix from $1,6002020-08-26 MEDIUM 6.1 CVE-2018-11011 ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java. Halo No fix yet Fix from $1,6002018-05-12 MEDIUM 6.1 CVE-2018-11012 ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java. Halo No fix yet Fix from $1,6002018-05-12