Vulnerability index

Browse CVEs

30 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-70886 An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission end… Halo after 2.22.4 Fix from $1,9502026-02-12 MEDIUM 6.1 CVE-2025-44593 Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can … Halo 2.20.13+ Fix from $1,6002025-09-09 MEDIUM 6.1 CVE-2025-44595 Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}. Halo after 2.20.17 Fix from $1,6002025-09-09 CRITICAL 9.1 CVE-2025-44594 halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. Halo after 2.20.17 Fix from $2,3002025-09-09 CRITICAL 9.0 CVE-2024-56156 Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation contr… Halo 2.20.13+ Fix from $2,3002025-04-25 MEDIUM 6.4 CVE-2024-43793 Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vuln… Halo 2.19.0+ Fix from $1,6002024-09-11 MEDIUM 6.1 CVE-2024-43792 Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vuln… Halo 2.17.0+ Fix from $1,6002024-09-02 MEDIUM 6.1 CVE-2023-33528 halo v1.6.0 is vulnerable to Cross Site Scripting (XSS). Halo No fix yet Fix from $1,6002024-03-28 CRITICAL 9.8 CVE-2022-32994EPSS 17% Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. Halo No fix yet Fix from $2,3002022-06-27 CRITICAL 9.8 CVE-2022-32995EPSS 16% Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. Halo No fix yet Fix from $2,3002022-06-27 HIGH 7.5 CVE-2022-26619 Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. Halo No fix yet Fix from $1,9502022-04-05 MEDIUM 5.4 CVE-2021-43659 In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS v… Halo No fix yet Fix from $1,6002022-03-24 CRITICAL 9.1 CVE-2020-19038 File Deletion vulnerability in Halo 0.4.3 via delBackup. Halo No fix yet Fix from $2,3002021-07-12 HIGH 7.5 CVE-2020-23079 SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet. Halo after 1.3.2 Fix from $1,9502021-07-12 MEDIUM 5.4 CVE-2020-18982 Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl. Halo No fix yet Fix from $1,6002021-07-12 MEDIUM 5.3 CVE-2020-19037 Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies. Halo No fix yet Fix from $1,6002021-07-12 CRITICAL 9.8 CVE-2020-18980 Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters. Halo No fix yet Fix from $2,3002021-07-12 MEDIUM 6.1 CVE-2020-18979 Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter. Halo No fix yet Fix from $1,6002021-07-12 MEDIUM 6.1 CVE-2020-21345 Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute ar… Halo No fix yet Fix from $1,6002021-05-20 CRITICAL 9.8 CVE-2020-21526 An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on… Halo No fix yet Fix from $2,3002020-09-30 CRITICAL 9.1 CVE-2020-21524 There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/word… Halo No fix yet Fix from $2,3002020-09-30 HIGH 7.7 CVE-2020-21527 There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files… Halo Mitigation only Fix from $1,9502020-09-30 HIGH 7.5 CVE-2020-21525 Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the … Halo No fix yet Fix from $1,9502020-09-30 CRITICAL 9.8 CVE-2020-21522 An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ft… Halo No fix yet Fix from $2,3002020-09-30 CRITICAL 9.8 CVE-2020-21523 A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the… Halo No fix yet Fix from $2,3002020-09-30 MEDIUM 5.4 CVE-2020-19007 Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then… Halo No fix yet Fix from $1,6002020-08-26 HIGH 7.2 CVE-2019-19999 Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker conf… Halo after 1.1.1 Fix from $1,9502019-12-26 MEDIUM 5.4 CVE-2019-16890 Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments. Halo Patch available Fix from $1,6002019-09-25 MEDIUM 6.1 CVE-2018-11011 ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java. Halo No fix yet Fix from $1,6002018-05-12 MEDIUM 6.1 CVE-2018-11012 ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java. Halo No fix yet Fix from $1,6002018-05-12