VYPR

Halo

by Halo Dev

Source repositories

CVEs (47)

  • CVE-2026-36758MedApr 30, 2026
    risk 0.28cvss 4.3epss 0.00

    A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • CVE-2025-14117MedDec 6, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early…

  • CVE-2025-15141LowDec 28, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed from remote. This attack is…

  • CVE-2026-16088MedJul 18, 2026
    risk 0.00cvss 4.7epss 0.00

    A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. Performing a manipulation results in path traversal. The attack is possible to be…

  • CVE-2026-15326LowJul 10, 2026
    risk 0.00cvss 3.8epss 0.00

    A vulnerability was identified in halo-dev halo up to 2.24.2. This affects the function ThemeUtils.unzipThemeTo of the file ThemeUtils.java of the component Theme Installation. Such manipulation of the argument metadata.name leads to path traversal. The attack may be launched…

  • CVE-2026-55439MedJun 25, 2026
    risk 0.00cvss 5.5epss 0.00

    Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated administrators to read arbitrary files from the server filesystem. The backup download endpoint (GET…

  • CVE-2024-56156CriApr 25, 2025
    risk 0.00cvss 9.0epss 0.01

    Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which can lead to stored cross-site…

Page 3 of 3