Wallosapp
Wallosapp Wallos: vulnerabilidades y CVE
Wallosapp Wallos tiene 33 vulnerabilidades publicadas, 28 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE33
Últimos 12 meses28
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-77353 | Media (4.6) | 0.29% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by… |
| CVE-2026-77352 | Media (4.3) | 0.33% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound… |
| CVE-2026-77351 | Baja (3.5) | 0.29% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in… |
| CVE-2026-77348 | Alta (8.2) | 0.43% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened… |
| CVE-2026-61641 | Alta (8.1) | 0.53% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email… |
| CVE-2026-61640 | Alta (8.5) | 0.54% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in… |
| CVE-2026-61639 | Alta (8.5) | 0.51% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads… |
| CVE-2026-61638 | Alta (8.2) | 0.50% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF… |
| CVE-2026-54600 | Alta (8.2) | 0.58% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured… |
| CVE-2026-54599 | Alta (7.5) | 0.22% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback… |
| CVE-2026-54598 | Alta (7.5) | 0.46% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any… |
| CVE-2026-50199 | Media (4.3) | 0.26% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential… |
| CVE-2026-50198 | Media (4.3) | 0.29% | — | 31 ago 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID… |
| CVE-2026-41689 | Media (6) | 0.27% | — | 7 may 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an administrator-configured local-target allowlist for every logged-in user.… |
| CVE-2026-41688 | Alta (7.7) | 0.39% | — | 7 may 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL… |
| CVE-2026-41687 | Media (4.3) | 0.33% | — | 7 may 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in endpoints/subscription/add.php (line 42) and endpoints/payments/add.php (line 40) uses an inline IP… |
| CVE-2026-33417 | Alta (7.1) | 0.31% | — | 24 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the… |
| CVE-2026-33407 | Alta (8.3) | 0.53% | — | 24 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF… |
| CVE-2026-33401 | Alta (7.1) | 0.41% | — | 24 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left… |
| CVE-2026-33400 | Media (5.4) | 0.29% | — | 24 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authenticated user to… |
| CVE-2026-33399 | Alta (7.7) | 0.40% | — | 24 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The… |
| CVE-2026-30842 | Media (4.3) | 0.34% | — | 7 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user to delete avatar files uploaded by other users. The avatar deletion endpoint does not… |
| CVE-2026-30841 | Media (6.9) | 0.34% | — | 7 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["email"] directly into HTML input value attributes using <?= $token ?>… |
| CVE-2026-30840 | Alta (8.8) | 0.54% | — | 7 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2. |
| CVE-2026-30839 | Media (5.3) | 0.37% | — | 7 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.php does not validate the target URL against private/reserved IP ranges, enabling full-read SSRF.… |
| CVE-2026-30828 | Alta (8.7) | 0.51% | — | 7 mar 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2. |
| CVE-2026-27479 | Alta (7.7) | 0.43% | — | 21 feb 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon upload functionality.… |
| CVE-2025-60535 | Alta (7.3) | 0.15% | — | 14 oct 2025 | A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request. |
| CVE-2024-55372 | Crítica (9.8) | 0.64% | — | 16 abr 2025 | Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server.… |
| CVE-2024-55371 | Crítica (9.8) | 0.62% | — | 16 abr 2025 | Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.