Halo maintains a narrowly scoped product line centered on a single platform that ranks among the more prominent entities tracked in the vulnerability landscape. The vendor's disclosures skew strongly toward critical-severity outcomes, concentrated across a persistent set of web-application vulnerabilities including cross-site scripting, path traversal, server-side request forgery, and unrestricted file upload, which recur across versions and reflect common input-handling and access-control gaps in web-facing applications. The vulnerability profile suggests an application with significant exposure to untrusted user input and external requests; defenders should treat advisories for this product as high-priority given the severity tendency and broadly applicable impact on installations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Halo over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32995CRITICAL Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function. | Jun 27, 2022 | 9.8 | 39 | NO | NO |
CVE-2022-32994CRITICAL Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload. | Jun 27, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-18980CRITICAL Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters. | Jul 12, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-21523CRITICAL A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This | Sep 30, 2020 | 9.8 | 29 | NO | NO |
CVE-2020-21526CRITICAL An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but | Sep 30, 2020 | 9.8 | 28 | NO | NO |
CVE-2020-21522CRITICAL An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the u | Sep 30, 2020 | 9.8 | 28 | NO | NO |
CVE-2025-44594CRITICAL halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url. | Sep 9, 2025 | 9.1 | 27 | NO | NO |
CVE-2020-19038CRITICAL File Deletion vulnerability in Halo 0.4.3 via delBackup. | Jul 12, 2021 | 9.1 | 27 | NO | NO |
CVE-2020-21524CRITICAL There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/wordpress) needs to parse the xml f | Sep 30, 2020 | 9.1 | 27 | NO | NO |
CVE-2022-26619HIGH Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function. | Apr 5, 2022 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Halo.
Media articles that mention a CVE ID that affects a product developed by Halo — matched by CVE ID, not by vendor name.