Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Wallos — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in Wallos, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting Wallos, a web-based business management application, primarily categorized by common weakness types such as cross-site scripting, remote code execution, and improper input validation. The collection covers reported security defects across various versions of the product, spanning a defined historical timeframe that reflects the evolution of the software's security posture. Visitors can use this resource to track the vendor's advisory history, understand specific weakness classes impacting the application, and review the complete vulnerability record for this product. The data is organized to support systematic review of security issues, allowing analysts to identify recurring patterns and assess the overall risk profile without relying on marketing language. This aggregation serves as a factual reference for evaluating past security incidents and informing future remediation strategies.

Vendor: ellite

CVE ID Title CVSS Severity Published
CVE-2026-77353 Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export CWE-74 4.6 Medium 2026-08-31
CVE-2026-77352 Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) CWE-918 4.3 Medium 2026-08-31
CVE-2026-77348 Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php` CWE-441 8.2 High 2026-08-31
CVE-2026-77351 Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings CWE-918 3.5 Low 2026-08-31
CVE-2026-61641 Wallos: OIDC account takeover via email-based account linking without `email_verified` check CWE-287 8.1 High 2026-08-31
CVE-2026-61640 Wallos: SSRF via OIDC Token/UserInfo URL Configuration CWE-918 8.5 High 2026-08-31
CVE-2026-61639 Wallos: Zip Slip path traversal in database restore writes files to webroot CWE-22 8.5 High 2026-08-31
CVE-2026-61638 Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port CWE-918 8.2 High 2026-08-31
CVE-2026-54600 Wallos: Unauthenticated database replacement via import endpoint on fresh install CWE-287 8.2 High 2026-08-31
CVE-2026-54599 Wallos: OIDC state parameter never validated — login CSRF / account takeover CWE-352 7.5 High 2026-08-31
CVE-2026-54598 Missing Authentication for Critical Function in wallos CWE-306 7.5 High 2026-08-31
CVE-2026-50199 Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh CWE-863 4.3 Medium 2026-08-31
CVE-2026-50198 Wallos: Cross-user subscription cost inference via replacement_subscription_id CWE-639 4.3 Medium 2026-08-31
CVE-2026-41689 Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services CWE-863 6.0 Medium 2026-05-07
CVE-2026-41688 Incomplete fix for CVE-2026-33399: SSRF in Wallos CWE-918 7.7 High 2026-05-07
CVE-2026-41687 Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks CWE-918 4.3 Medium 2026-05-07
CVE-2026-33417 Wallos: Password Reset Tokens Never Expire CWE-613 6.5 Medium 2026-03-24
CVE-2026-33401 Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php CWE-918 8.1 - 2026-03-24
CVE-2026-33400 Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint CWE-79 5.4 Medium 2026-03-24
CVE-2026-33399 Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840 CWE-918 7.7 High 2026-03-24
CVE-2026-33407 Wallos: SSRF via HTTP Proxy Environment Variable CWE-918 8.2 - 2026-03-24
CVE-2026-30842 Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars CWE-862 4.3 Medium 2026-03-07
CVE-2026-30841 Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php CWE-79 6.1 - 2026-03-07
CVE-2026-30840 Wallos: Server-Side Request Forgery (SSRF) in Notification Testers CWE-918 9.8 - 2026-03-07
CVE-2026-30839 Wallos: SSRF via webhook test endpoint CWE-918 6.5 - 2026-03-07
CVE-2026-30828 Wallos: SSRF via url parameter leading to File Traversal CWE-29 7.5 - 2026-03-07
CVE-2026-27479 Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch CWE-918 7.7 High 2026-02-21

All 27 known CVE vulnerabilities affecting Wallos with full Chinese analysis, references, and POCs where available.