6.9

CVSS4.0

CVE-2026-30841 - Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.php

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["email"] directly into HTML input value attributes using <?= $token ?> and <?= $email ?> without calling htmlspecialchars(). This allows reflected XSS by…

πŸ“… Published: March 7, 2026, 5:40 a.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

8.8

CVSS3.0

CVE-2026-30840 - Wallos: Server-Side Request Forgery (SSRF) in Notification Testers

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This issue has been patched in version 4.6.2.

πŸ“… Published: March 7, 2026, 5:39 a.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.

5.3

CVSS4.0

CVE-2026-30839 - Wallos: SSRF via webhook test endpoint

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, testwebhooknotifications.php does not validate the target URL against private/reserved IP ranges, enabling full-read SSRF. The server response is returned to the caller. This issue has been patched in ver…

πŸ“… Published: March 7, 2026, 5:29 a.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.

8.7

CVSS4.0

CVE-2026-30828 - Wallos: SSRF via url parameter leading to File Traversal

Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been patched in version 4.6.2.

πŸ“… Published: March 7, 2026, 5:27 a.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

7.5

CVSS3.1

CVE-2026-30827 - express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting (all IPv4 clients sh…

express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in express-rate-limit applies IPv6 subnet masking (/56 by default) to all addresses that net.isIPv6() returns true for. …

πŸ“… Published: March 7, 2026, 5:19 a.m. πŸ”„ Last Modified: April 17, 2026, 12:15 p.m.

0

CVSS3.1

CVE-2026-30825 - hoppscotch: IDOR - Any authenticated user can revoke any other user's Personal Access Token

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.1, the DELETE /v1/access-tokens/revoke endpoint allows any authenticated user to delete any other user's PAT by providing its ID, with no ownership verification. This issue has been patched in version 2026.2.1.

πŸ“… Published: March 7, 2026, 5:13 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.

7.7

CVSS4.0

CVE-2026-30824 - Flowise: Missing Authentication on NVIDIA NIM Endpoints

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the NVIDIA NIM router (/api/v1/nvidia-nim/*) is whitelisted in the global authentication middleware, allowing unauthenticated access to privileged container management and token generat…

πŸ“… Published: March 7, 2026, 5:11 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.

8.8

CVSS3.0

CVE-2026-30823 - Flowise: IDOR leading to Account Takeover and Enterprise Feature Bypass via SSO Configuration

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, there is an IDOR vulnerability, leading to account takeover and enterprise feature bypass via SSO configuration. This issue has been patched in version 3.0.13.

πŸ“… Published: March 7, 2026, 5:10 a.m. πŸ”„ Last Modified: April 18, 2026, 5:30 p.m.

7.7

CVSS3.0

CVE-2026-30822 - Flowise: Mass Assignment in `/api/v1/leads` Endpoint

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, unauthenticated users can inject arbitrary values into internal database fields when creating leads. This issue has been patched in version 3.0.13.

πŸ“… Published: March 7, 2026, 5:08 a.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.

8.2

CVSS4.0

CVE-2026-30821 - Flowise: Arbitrary File Upload via MIME Spoofing

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on the…

πŸ“… Published: March 7, 2026, 5:07 a.m. πŸ”„ Last Modified: April 16, 2026, 11:15 a.m.
Total resulsts: 349182
Page 1266 of 34,919
Β« previous page Β» next page
Filters