VYPR
Vendor

Walla Telesite

Products
3
CVEs
16
Across products
17
Status
Private

Products

3

Recent CVEs

16
  • CVE-2026-82089HigAug 28, 2026
    risk 0.57cvss epss

    The wallabag (aka fr.gaulupeau.apps.InThePoche) application through 2.6.0 for Android allows XSS because /api/entries data is loaded into a WebView.

  • CVE-2026-82081MedAug 28, 2026
    risk 0.42cvss 6.4epss

    wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.

  • CVE-2023-0737MedNov 15, 2024
    risk 0.35cvss 6.5epss 0.00

    wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This issue is fixed in version 2.5.4.

  • CVE-2023-4455MedAug 21, 2023
    risk 0.35cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

  • CVE-2023-0735MedFeb 7, 2023
    risk 0.35cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4.

  • CVE-2023-4454MedAug 21, 2023
    risk 0.30cvss 5.7epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3.

  • CVE-2023-0736MedFeb 7, 2023
    risk 0.28cvss 5.4epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4.

  • CVE-2023-0734MedMar 5, 2023
    risk 0.27cvss 5.3epss 0.01

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4.

  • CVE-2018-11352MedSep 21, 2018
    risk 0.26cvss 4.0epss 0.01

    The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The…

  • CVE-2023-3566LowJul 10, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Profile Config. The manipulation of the argument Name leads to allocation of resources. The exploit…

  • CVE-2023-0610MedFeb 1, 2023
    risk 0.21cvss 4.3epss 0.00

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

  • CVE-2023-0609MedFeb 1, 2023
    risk 0.21cvss 4.3epss 0.01

    Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.

  • CVE-2005-3579Nov 16, 2005
    risk 0.03cvss epss 0.03

    ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the querystring.

  • CVE-2005-3577Nov 16, 2005
    risk 0.03cvss epss 0.02

    Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the sug parameter.

  • CVE-2005-3578Nov 16, 2005
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject arbitrary SQL commands via the sug parameter.

  • CVE-2005-3576Nov 16, 2005
    risk 0.03cvss epss 0.03

    ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the article number in tsurl parameter.