Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Ech0 — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Ech0, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerability data specifically for the software product Ech0, focusing on reported weaknesses, assigned identifiers, and associated risk tags. It collects confirmed security issues, including buffer overflows, logic errors, and denial-of-service conditions, covering incidents documented from the initial public release through the most recent maintenance updates. Readers can utilize this dataset to track the vendor’s advisory history, analyze the prevalence of specific weakness classes within the codebase, or review the complete vulnerability lifecycle for this particular software component. By examining the aggregated metrics, security teams and researchers can identify recurring patterns in exploitability, assess the timeliness of patches, and understand the broader context of how Ech0 fits within its wider ecosystem. The entries are normalized to standard classifications, allowing for cross-referencing with other security intelligence sources without the noise of redundant or unverified claims. This centralized view removes the need to scan multiple disparate sources, providing a single, coherent timeline of security events. Whether you are evaluating supply chain risks or conducting a deep dive into specific coding errors, this compilation offers the factual foundation necessary for informed decision-making. The data is updated regularly as new disclosures are published by relevant security authorities, ensuring the information remains current and relevant for ongoing monitoring and compliance activities.

Vendor: lin-snow

CVE ID Title CVSS Severity Published
CVE-2026-79673 Ech0 before 4.4.3 Scope Bypass via profile:read Token CWE-863 6.5 Medium 2026-08-25
CVE-2026-79672 Ech0 before 4.4.3 Authentication Bypass via Comment Panel CWE-862 5.5 Medium 2026-08-25
CVE-2026-79671 Ech0 before 4.4.3 SSRF via DNS Resolution Bypass CWE-918 5.5 Medium 2026-08-25
CVE-2026-79670 Ech0 before 4.4.3 Stored XSS via SVG Upload CWE-434 4.8 Medium 2026-08-25
CVE-2026-79669 Ech0 before 4.4.3 Missing Authorization on System Logs CWE-862 4.3 Medium 2026-08-25
CVE-2026-79668 Ech0 before 4.7.3 Unauthenticated Like Endpoint Metric Inflation CWE-306 5.3 Medium 2026-08-25
CVE-2026-79666 Ech0 before 4.4.3 Missing Authorization via dashboard log endpoints CWE-862 6.5 Medium 2026-08-25
CVE-2026-79667 Ech0 before 4.4.3 Authentication Bypass via Scope Enforcement CWE-285 7.6 High 2026-08-25
CVE-2026-79665 Ech0 before 4.5.1 Authorization Bypass via Session Tokens CWE-862 8.8 High 2026-08-25
CVE-2026-79663 Ech0 before 4.7.3 Stored XSS via RSS feed tag names CWE-79 4.8 Medium 2026-08-25
CVE-2026-79664 Ech0 before 4.7.3 Access Token Revocation Bypass CWE-613 7.4 High 2026-08-25
CVE-2026-79662 Ech0 before 4.7.3 OAuth Redirect URI Validation Bypass CWE-601 8.0 High 2026-08-25
CVE-2026-79660 Ech0 before 4.7.3 Email Disclosure via Public API CWE-200 5.3 Medium 2026-08-25
CVE-2026-79661 Ech0 before 4.7.3 Unauthenticated fav_count Modification CWE-770 6.5 Medium 2026-08-25
CVE-2026-79659 Ech0 before 4.7.3 Server-Side Request Forgery via fetchPeerConnectInfo CWE-918 7.7 High 2026-08-25
CVE-2026-79658 Ech0 before 5.0.1 Denial of Service via Accept-Language CWE-400 7.5 High 2026-08-25
CVE-2026-77151 lin-snow Ech0 crypto.go MD5Encrypt risky encryption CWE-327 3.7 Low 2026-08-20
CVE-2026-35037 Ech0 affected by unauthenticated SSRF in GetWebsiteTitle allows access to internal services and cloud metadata CWE-918 7.2 High 2026-04-06
CVE-2026-35036 Ech0 Affected by Unauthenticated Server-Side Request Forgery in Website Preview Feature CWE-918 7.5 High 2026-04-06
CVE-2026-33638 Ech0 authenticated user-list exposed data via public `/api/allusers` endpoint CWE-862 5.3 Medium 2026-03-26

All 20 known CVE vulnerabilities affecting Ech0 with full Chinese analysis, references, and POCs where available.