Wallabag/wallabag
Source repositories
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-82089 | Hig | 0.57 | — | — | Aug 28, 2026 | The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView. | ||
| CVE-2026-82081 | Med | 0.42 | 6.4 | — | Aug 28, 2026 | wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export. | ||
| CVE-2023-0737 | Med | 0.35 | 6.5 | 0.00 | Nov 15, 2024 | wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4. | ||
| CVE-2023-4455 | Med | 0.35 | 6.5 | 0.00 | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. | ||
| CVE-2023-0735 | Med | 0.35 | 6.5 | 0.00 | Feb 7, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4. | ||
| CVE-2023-4454 | Med | 0.30 | 5.7 | 0.00 | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. | ||
| CVE-2023-0736 | Med | 0.28 | 5.4 | 0.00 | Feb 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4. | ||
| CVE-2023-0734 | Med | 0.27 | 5.3 | 0.01 | Mar 5, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. | ||
| CVE-2018-11352 | Med | 0.26 | 4.0 | 0.01 | Sep 21, 2018 | The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The… | ||
| CVE-2023-3566 | Low | 0.23 | 3.5 | 0.01 | Jul 10, 2023 | A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit… | ||
| CVE-2023-0610 | Med | 0.21 | 4.3 | 0.00 | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. | ||
| CVE-2023-0609 | Med | 0.21 | 4.3 | 0.01 | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. |
- risk 0.57cvss —epss —
The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.
- risk 0.42cvss 6.4epss —
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.
- risk 0.35cvss 6.5epss 0.00
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
- risk 0.35cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.
- risk 0.30cvss 5.7epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
- risk 0.28cvss 5.4epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.
- risk 0.27cvss 5.3epss 0.01
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
- risk 0.26cvss 4.0epss 0.01
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The…
- risk 0.23cvss 3.5epss 0.01
A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit…
- risk 0.21cvss 4.3epss 0.00
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
- risk 0.21cvss 4.3epss 0.01
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.