Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Halo

First CVE: May 12, 2018Active for: 8 yearsTotal CVEs: 33
37.9
VTI Score
Medium

Halo maintains a narrowly scoped product line centered on a single platform that ranks among the more prominent entities tracked in the vulnerability landscape. The vendor's disclosures skew strongly toward critical-severity outcomes, concentrated across a persistent set of web-application vulnerabilities including cross-site scripting, path traversal, server-side request forgery, and unrestricted file upload, which recur across versions and reflect common input-handling and access-control gaps in web-facing applications. The vulnerability profile suggests an application with significant exposure to untrusted user input and external requests; defenders should treat advisories for this product as high-priority given the severity tendency and broadly applicable impact on installations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
3.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.1
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Halo over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 12, 2018
8 years ago
Most Recent CVE
Feb 12, 2026
162 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-32995CRITICAL
Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.
Jun 27, 20229.839NONO
CVE-2022-32994CRITICAL
Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.
Jun 27, 20229.832NONO
CVE-2020-18980CRITICAL
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
Jul 12, 20219.830NONO
CVE-2020-21523CRITICAL
A Server-Side Freemarker template injection vulnerability in halo CMS v1.1.3 In the Edit Theme File function. The ftl file can be edited. This is the Freemarker template file. This
Sep 30, 20209.829NONO
CVE-2020-21526CRITICAL
An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but
Sep 30, 20209.828NONO
CVE-2020-21522CRITICAL
An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the u
Sep 30, 20209.828NONO
CVE-2025-44594CRITICAL
halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.
Sep 9, 20259.127NONO
CVE-2020-19038CRITICAL
File Deletion vulnerability in Halo 0.4.3 via delBackup.
Jul 12, 20219.127NONO
CVE-2020-21524CRITICAL
There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/wordpress) needs to parse the xml f
Sep 30, 20209.127NONO
CVE-2022-26619HIGH
Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.
Apr 5, 20227.525NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
48%
18%
30%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network33 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low32 (97.0%)
High1 (3.0%)
Unknown0 (0.0%)
User Interaction
None18 (54.5%)
Unknown0 (0.0%)
Required15 (45.5%)
Privileges Required
Low8 (24.2%)
High3 (9.1%)
None22 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Halo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Halo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Halo's Products

View all 4 CNAs →

Top CWEs