« Volver al listado

Wallosapp

Wallosapp Wallos: vulnerabilidades y CVE

Wallosapp Wallos tiene 33 vulnerabilidades publicadas, 28 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE33
Últimos 12 meses28
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-77353Media (4.6)0.29%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by…
CVE-2026-77352Media (4.3)0.33%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound…
CVE-2026-77351Baja (3.5)0.29%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in…
CVE-2026-77348Alta (8.2)0.43%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened…
CVE-2026-61641Alta (8.1)0.53%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incoming OIDC identity to an existing local account by matching the email…
CVE-2026-61640Alta (8.5)0.54%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, Admin-configured OIDC token_url and user_info_url in includes/oidc/handle_oidc_callback.php:18-49 are used directly in…
CVE-2026-61639Alta (8.5)0.51%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/db/restore.php calls ZipArchive::extractTo() without validating entry names for ../ sequences. Admin uploads…
CVE-2026-61638Alta (8.2)0.50%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.6, POST /endpoints/notifications/testemailnotifications.php accepts smtpaddress and smtpport from POST body with zero SSRF…
CVE-2026-54600Alta (8.2)0.58%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/import.php has no authentication. The only guard is a user-table row count — if zero (fresh/unconfigured…
CVE-2026-54599Alta (7.5)0.22%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, login.php generates an OIDC state nonce stored in $_SESSION['oidc_state'], but checksession.php dispatches the OIDC callback…
CVE-2026-54598Alta (7.5)0.46%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.4, endpoints/db/migrate.php executes database schema migrations when called over HTTP with zero authentication. Any…
CVE-2026-50199Media (4.3)0.26%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, endpoints/currency/update_exchange.php loads the first Fixer/API Layer credential globally instead of loading the credential…
CVE-2026-50198Media (4.3)0.29%—31 ago 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.9.1, an authenticated user can edit their own inactive subscription and set replacement_subscription_id to a subscription ID…
CVE-2026-41689Media (6)0.27%—7 may 2026
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notification feature reuses an administrator-configured local-target allowlist for every logged-in user.…
CVE-2026-41688Alta (7.7)0.39%—7 may 2026
Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF fix in Wallos validates webhook URLs via gethostbyname() but passes the original hostname to cURL…
CVE-2026-41687Media (4.3)0.33%—7 may 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in endpoints/subscription/add.php (line 42) and endpoints/payments/add.php (line 40) uses an inline IP…
CVE-2026-33417Alta (7.1)0.31%—24 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a created_at timestamp column, but the…
CVE-2026-33407Alta (8.3)0.53%—24 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment variables without validation, enabling SSRF…
CVE-2026-33401Alta (7.1)0.41%—24 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left…
CVE-2026-33400Media (5.4)0.29%—24 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authenticated user to…
CVE-2026-33399Alta (7.7)0.40%—24 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomplete. The…
CVE-2026-30842Media (4.3)0.34%—7 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, Wallos allows an authenticated user to delete avatar files uploaded by other users. The avatar deletion endpoint does not…
CVE-2026-30841Media (6.9)0.34%—7 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["email"] directly into HTML input value attributes using <?= $token ?>…
CVE-2026-30840Alta (8.8)0.54%—7 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.
CVE-2026-30839Media (5.3)0.37%—7 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.php does not validate the target URL against private/reserved IP ranges, enabling full-read SSRF.…
CVE-2026-30828Alta (8.7)0.51%—7 mar 2026
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2.
CVE-2026-27479Alta (7.7)0.43%—21 feb 2026
Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and payment logo/icon upload functionality.…
CVE-2025-60535Alta (7.3)0.15%—14 oct 2025
A Cross-Site Request Forgery (CSRF) in the component /endpoints/currency/currency of Wallos v4.1.1 allows attackers to execute arbitrary operations via a crafted GET request.
CVE-2024-55372Crítica (9.8)0.64%—16 abr 2025
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server.…
CVE-2024-55371Crítica (9.8)0.62%—16 abr 2025
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server.…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application10
  2. T1090 Proxy8
  3. T1210 Exploitation of Remote Services7
  4. T1078 Valid Accounts3
  5. T1505.003 Web Shell3
  6. T1203 Exploitation for Client Execution2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.