VYPR

Wallos

by Wallos

CVEs (5)

  • CVE-2024-55372CriApr 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to…

  • CVE-2024-55371CriApr 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an…

  • CVE-2024-29320HigApr 30, 2024
    risk 0.53cvss 8.1epss 0.01

    Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

  • CVE-2024-57386MedJan 23, 2025
    risk 0.40cvss 6.1epss 0.00

    Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.

  • CVE-2024-22776MedFeb 23, 2024
    risk 0.31cvss 4.7epss 0.00

    Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.