VendorsWallosappwallosall versions
Vulnerabilities

Wallosapp Wallos

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

16CVEs
CVE-2024-55372
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
Published 2025-04-16 · Analyzed
9.8EPSS 0.006
CVE-2024-55371
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
Published 2025-04-16 · Analyzed
9.8EPSS 0.006
CVE-2026-33407
Wallos: SSRF via HTTP Proxy Environment Variable
Published 2026-03-24 · Analyzed
9.1EPSS 0.005
CVE-2026-30840
Wallos: Server-Side Request Forgery (SSRF) in Notification Testers
Published 2026-03-07 · Analyzed
8.8EPSS 0.005
CVE-2026-30828
Wallos: SSRF via url parameter leading to File Traversal
Published 2026-03-07 · Analyzed
8.7EPSS 0.005
CVE-2024-29320
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
Published 2024-04-30 · Analyzed
8.1EPSS 0.007
CVE-2026-27479
Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch
Published 2026-02-21 · Analyzed
7.7EPSS 0.004
CVE-2026-33399
Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840
Published 2026-03-24 · Analyzed
7.7EPSS 0.004
CVE-2026-33401
Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php
Published 2026-03-24 · Analyzed
7.1EPSS 0.004
CVE-2026-33417
Wallos: Password Reset Tokens Never Expire
Published 2026-03-24 · Analyzed
7.1EPSS 0.003
CVE-2026-30841
Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php
Published 2026-03-07 · Analyzed
6.9EPSS 0.003
CVE-2024-57386
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture function.
Published 2025-01-23 · Analyzed
6.1EPSS 0.005
CVE-2026-33400
Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint
Published 2026-03-24 · Analyzed
5.4EPSS 0.003
CVE-2026-30839
Wallos: SSRF via webhook test endpoint
Published 2026-03-07 · Analyzed
5.3EPSS 0.004
CVE-2024-22776
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those requiring specific formats like date fields.
Published 2024-02-23 · Analyzed
4.7EPSS 0.005
CVE-2026-30842
Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars
Published 2026-03-07 · Analyzed
4.3EPSS 0.003