Vulnerability index

Browse CVEs

13 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-33417 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The pass… Wallos 4.7.2+ Fix from $1,9502026-03-24 CRITICAL 9.1 CVE-2026-33407 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY a… Wallos 4.7.0+ Fix from $2,3002026-03-24 HIGH 7.7 CVE-2026-33399 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-308… Wallos 4.7.0+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33401 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-308… Wallos 4.7.0+ Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2026-33400 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in t… Wallos 4.7.0+ Fix from $1,6002026-03-24 HIGH 8.8 CVE-2026-30840 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability i… Wallos 4.6.2+ Fix from $1,9502026-03-07 MEDIUM 6.1 CVE-2026-30841 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["em… Wallos 4.6.2+ Fix from $1,6002026-03-07 HIGH 7.5 CVE-2026-30828 Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system… Wallos 4.6.2+ Fix from $1,9502026-03-07 HIGH 7.7 CVE-2026-27479 Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerab… Wallos 4.6.1+ Fix from $1,9502026-02-21 CRITICAL 9.8 CVE-2024-55371 Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a Z… Wallos after 2.38.2 Fix from $2,3002025-04-16 CRITICAL 9.8 CVE-2024-55372 Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading… Wallos after 2.38.2 Fix from $2,3002025-04-16 MEDIUM 6.1 CVE-2024-57386 Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function. Wallos No fix yet Fix from $1,6002025-01-23 HIGH 8.1 CVE-2024-29320 Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. Wallos 1.15.3+ Fix from $1,9502024-04-30