VYPR

Wallabag/wallabag

by Walla Telesite

CVEs (8)

  • CVE-2023-0737Nov 15, 2024
    risk 0.00cvss epss 0.00

    wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.

  • CVE-2023-4455Aug 21, 2023
    risk 0.00cvss epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

  • CVE-2023-4454Aug 21, 2023
    risk 0.00cvss epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

  • CVE-2023-0734Mar 5, 2023
    risk 0.00cvss epss 0.00

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

  • CVE-2023-0735Feb 7, 2023
    risk 0.00cvss epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.

  • CVE-2023-0736Feb 7, 2023
    risk 0.00cvss epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.

  • CVE-2023-0609Feb 1, 2023
    risk 0.00cvss epss 0.00

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

  • CVE-2023-0610Feb 1, 2023
    risk 0.00cvss epss 0.00

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.