Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Wallos HIGH 7.1
CVE-2026-33417

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The pass…

Fix: 4.7.2+
Fix from $1,950 2026-03-24
Wallos CRITICAL 9.1
CVE-2026-33407

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY a…

Fix: 4.7.0+
Fix from $2,300 2026-03-24
Wallos HIGH 7.7
CVE-2026-33399

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-308…

Fix: 4.7.0+
Fix from $1,950 2026-03-24
Wallos MEDIUM 6.5
CVE-2026-33401

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-308…

Fix: 4.7.0+
Fix from $1,600 2026-03-24
Wallos MEDIUM 5.4
CVE-2026-33400

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in t…

Fix: 4.7.0+
Fix from $1,600 2026-03-24
Wallos HIGH 8.8
CVE-2026-30840

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability i…

Fix: 4.6.2+
Fix from $1,950 2026-03-07
Wallos MEDIUM 6.1
CVE-2026-30841

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["em…

Fix: 4.6.2+
Fix from $1,600 2026-03-07
Wallos HIGH 7.5
CVE-2026-30828

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system…

Fix: 4.6.2+
Fix from $1,950 2026-03-07
Wallos HIGH 7.7
CVE-2026-27479

Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerab…

Fix: 4.6.1+
Fix from $1,950 2026-02-21
Wallos CRITICAL 9.8
CVE-2024-55371

Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a Z…

Fix: after 2.38.2
Fix from $2,300 2025-04-16
Wallos CRITICAL 9.8
CVE-2024-55372

Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading…

Fix: after 2.38.2
Fix from $2,300 2025-04-16
Wallos MEDIUM 6.1
CVE-2024-57386

Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.

No fix yet
Fix from $1,600 2025-01-23
Wallos HIGH 8.1
CVE-2024-29320

Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

Fix: 1.15.3+
Fix from $1,950 2024-04-30