Wallabag is a self-hosted web content-curation and read-it-later application that allows users to save and organize articles for offline reading. Its vulnerability profile concentrates in web-application input handling and access control, with recurring weaknesses including cross-site request forgery, improper authorization, cross-site scripting, and resource-exhaustion conditions that are characteristic of server-side web applications handling user-submitted content. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wallabag over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0737MEDIUM wallabag version 2.5.2 contains a Cross-Site Request Forgery (CSRF) vulnerability that allows attackers to arbitrarily delete user accounts via the /account/delete endpoint. This i | Nov 15, 2024 | 6.5 | 20 | NO | NO |
CVE-2023-0736MEDIUM Cross-site Scripting (XSS) - Stored in GitHub repository wallabag/wallabag prior to 2.5.4. | Feb 7, 2023 | 5.4 | 20 | NO | NO |
CVE-2023-4455MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. | Aug 21, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-3566MEDIUM A vulnerability was found in wallabag 2.5.4. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /config of the component Pr | Jul 10, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-4454MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.6.3. | Aug 21, 2023 | 5.7 | 18 | NO | NO |
CVE-2023-0610MEDIUM Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. | Feb 1, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-0609MEDIUM Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3. | Feb 1, 2023 | 4.3 | 18 | NO | NO |
CVE-2023-0735MEDIUM Cross-Site Request Forgery (CSRF) in GitHub repository wallabag/wallabag prior to 2.5.4. | Feb 7, 2023 | 6.5 | 17 | NO | NO |
CVE-2018-11352MEDIUM The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the exe | Sep 21, 2018 | 4.0 | 17 | NO | NO |
CVE-2023-0734MEDIUM Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.4. | Mar 5, 2023 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wallabag.
Media articles that mention a CVE ID that affects a product developed by Wallabag — matched by CVE ID, not by vendor name.