VYPR

Halo CMS

by Halo CMS

CVEs (7)

  • CVE-2022-32995CriJun 27, 2022
    risk 0.65cvss 9.8epss 0.17

    Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.

  • CVE-2022-32994CriJun 27, 2022
    risk 0.65cvss 9.8epss 0.18

    Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.

  • CVE-2025-70886HigFeb 12, 2026
    risk 0.49cvss 7.5epss 0.00

    An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

  • CVE-2026-36759MedApr 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • CVE-2025-60898MedOct 29, 2025
    risk 0.38cvss 5.8epss 0.00

    An unauthenticated server-side request forgery (SSRF) vulnerability in the Thumbnail via-uri endpoint of Halo CMS 2.21 allows a remote attacker to cause the server to issue HTTP requests to attacker-controlled URLs, including internal addresses. The endpoint performs a…

  • CVE-2026-36756MedApr 30, 2026
    risk 0.35cvss 5.4epss 0.00

    A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • CVE-2026-36757MedApr 30, 2026
    risk 0.28cvss 4.3epss 0.00

    A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.