Ech0 is a modestly represented vendor with a focused product line centered on its flagship platform, where disclosed vulnerabilities cluster around server-side request forgery and missing authorization—both characteristic of web-application and API-handling surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ech0 over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-35036HIGH Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, Ech0 implements link preview (editor fetches a page title) through GET /api/websi | Apr 6, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-35037HIGH Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to 4.2.8, the GET /api/website/title endpoint accepts an arbitrary URL via the website_url | Apr 6, 2026 | 7.2 | 24 | NO | NO |
CVE-2026-33638MEDIUM Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/allusers` is mounted as a public endpoint and returns user reco | Mar 26, 2026 | 5.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ech0.
Media articles that mention a CVE ID that affects a product developed by Ech0 — matched by CVE ID, not by vendor name.