Home/Product/wallosapp wallos
Product

wallosapp wallos

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-33417
< 4.7.2
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos nev
6.5MEDIUM
CVE-2026-33407
< 4.7.0
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php a
9.1CRITICAL
CVE-2026-33401
< 4.7.0
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a5
6.5MEDIUM
CVE-2026-33400
< 4.7.0
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS)
5.4MEDIUM
CVE-2026-33399
< 4.7.0
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6
7.7HIGH
CVE-2026-30842
< 4.6.2
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user
4.3MEDIUM
CVE-2026-30841
< 4.6.2
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["to
6.1MEDIUM
CVE-2026-30840
< 4.6.2
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forg
8.8HIGH
CVE-2026-30839
< 4.6.2
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.php does n
4.3MEDIUM
CVE-2026-30828
< 4.6.2
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to re
7.5HIGH
CVE-2026-27479
< 4.6.1
Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forg
7.7HIGH
CVE-2024-55372
<= 2.38.2
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore da
9.8CRITICAL
CVE-2024-55371
<= 2.38.2
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backu
9.8CRITICAL
CVE-2024-57386
all versions
Cross Site Scripting vulnerability in Wallos v.2.41.0 allows a remote attacker to execute arbitrary code via the profile picture f
6.1MEDIUM
CVE-2024-29320
< 1.15.3
Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.
8.1HIGH
CVE-2024-22776
>= 0.9 and < 1.2.3
Wallos 0.9 is vulnerable to Cross Site Scripting (XSS) in all text-based input fields without proper validation, excluding those r
4.7MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin