Wallabag/wallabag
CVEs (8)
| CVE | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-0737 | 0.00 | — | 0.00 | Nov 15, 2024 | wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4. | ||
| CVE-2023-4455 | 0.00 | — | 0.00 | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. | ||
| CVE-2023-4454 | 0.00 | — | 0.00 | Aug 21, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. | ||
| CVE-2023-0734 | 0.00 | — | 0.00 | Mar 5, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. | ||
| CVE-2023-0735 | 0.00 | — | 0.00 | Feb 7, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4. | ||
| CVE-2023-0736 | 0.00 | — | 0.00 | Feb 7, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4. | ||
| CVE-2023-0609 | 0.00 | — | 0.00 | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. | ||
| CVE-2023-0610 | 0.00 | — | 0.00 | Feb 1, 2023 | Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. |
- CVE-2023-0737Nov 15, 2024risk 0.00cvss —epss 0.00
wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.
- CVE-2023-4455Aug 21, 2023risk 0.00cvss —epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
- CVE-2023-4454Aug 21, 2023risk 0.00cvss —epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.
- CVE-2023-0734Mar 5, 2023risk 0.00cvss —epss 0.00
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.
- CVE-2023-0735Feb 7, 2023risk 0.00cvss —epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.
- CVE-2023-0736Feb 7, 2023risk 0.00cvss —epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.
- CVE-2023-0609Feb 1, 2023risk 0.00cvss —epss 0.00
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
- CVE-2023-0610Feb 1, 2023risk 0.00cvss —epss 0.00
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.