Waline is a comment-system service designed for static-site and blog platforms, offering a lightweight alternative to traditional server-side comment infrastructure. The vendor's observed vulnerability profile centers on access-control weaknesses, particularly missing authorization checks that could expose comment data or administrative functionality to unintended actors. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Waline over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24594MEDIUM In waline 1.6.1, an attacker can submit messages using X-Forwarded-For to forge any IP address. | Feb 25, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Waline.
Media articles that mention a CVE ID that affects a product developed by Waline — matched by CVE ID, not by vendor name.