Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ellite — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting ellite. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ellette provides cloud-based collaboration and project management tools for businesses, enabling team communication and workflow optimization. Historically, the platform has been susceptible to multiple remote code execution, cross-site scripting, and privilege escalation vulnerabilities, with 14 CVEs documented. Common weaknesses include improper input validation and insecure direct object references. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities suggests potential risks for organizations relying on the platform. Security researchers have noted that some issues remained unpatched for extended periods, highlighting challenges in the vendor's vulnerability management process.

Top products by ellite: Wallos
CVE ID Title CVSS Severity Published
CVE-2026-77353 Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export — Wallos CWE-74 4.6 Medium 2026-08-31
CVE-2026-77352 Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user) — Wallos CWE-918 4.3 Medium 2026-08-31
CVE-2026-77348 Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php` — Wallos CWE-441 8.2 High 2026-08-31
CVE-2026-77351 Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings — Wallos CWE-918 3.5 Low 2026-08-31
CVE-2026-61641 Wallos: OIDC account takeover via email-based account linking without `email_verified` check — Wallos CWE-287 8.1 High 2026-08-31
CVE-2026-61640 Wallos: SSRF via OIDC Token/UserInfo URL Configuration — Wallos CWE-918 8.5 High 2026-08-31
CVE-2026-61639 Wallos: Zip Slip path traversal in database restore writes files to webroot — Wallos CWE-22 8.5 High 2026-08-31
CVE-2026-61638 Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port — Wallos CWE-918 8.2 High 2026-08-31
CVE-2026-54600 Wallos: Unauthenticated database replacement via import endpoint on fresh install — Wallos CWE-287 8.2 High 2026-08-31
CVE-2026-54599 Wallos: OIDC state parameter never validated — login CSRF / account takeover — Wallos CWE-352 7.5 High 2026-08-31
CVE-2026-54598 Missing Authentication for Critical Function in wallos — Wallos CWE-306 7.5 High 2026-08-31
CVE-2026-50199 Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh — Wallos CWE-863 4.3 Medium 2026-08-31
CVE-2026-50198 Wallos: Cross-user subscription cost inference via replacement_subscription_id — Wallos CWE-639 4.3 Medium 2026-08-31
CVE-2026-41689 Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services — Wallos CWE-863 6.0 Medium 2026-05-07
CVE-2026-41688 Incomplete fix for CVE-2026-33399: SSRF in Wallos — Wallos CWE-918 7.7 High 2026-05-07
CVE-2026-41687 Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks — Wallos CWE-918 4.3 Medium 2026-05-07
CVE-2026-33417 Wallos: Password Reset Tokens Never Expire — Wallos CWE-613 6.5 Medium 2026-03-24
CVE-2026-33401 Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php — Wallos CWE-918 8.1 - 2026-03-24
CVE-2026-33400 Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint — Wallos CWE-79 5.4 Medium 2026-03-24
CVE-2026-33399 Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840 — Wallos CWE-918 7.7 High 2026-03-24
CVE-2026-33407 Wallos: SSRF via HTTP Proxy Environment Variable — Wallos CWE-918 8.2 - 2026-03-24
CVE-2026-30842 Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatars — Wallos CWE-862 4.3 Medium 2026-03-07
CVE-2026-30841 Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php — Wallos CWE-79 6.1 - 2026-03-07
CVE-2026-30840 Wallos: Server-Side Request Forgery (SSRF) in Notification Testers — Wallos CWE-918 9.8 - 2026-03-07
CVE-2026-30839 Wallos: SSRF via webhook test endpoint — Wallos CWE-918 6.5 - 2026-03-07
CVE-2026-30828 Wallos: SSRF via url parameter leading to File Traversal — Wallos CWE-29 7.5 - 2026-03-07
CVE-2026-27479 Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetch — Wallos CWE-918 7.7 High 2026-02-21

This page lists every published CVE security advisory associated with ellite. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.