Wallosapp's vulnerability profile concentrates in a single web-based inventory-management application that sits in an application-layer role and skews toward serious outcomes, with a meaningful share reaching critical severity. The recurring weakness classes—including server-side request forgery, cross-site scripting, path traversal, improper certificate validation, and file-path manipulation—reflect the web application's exposure to input-handling, file-system access, and network-request attack surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wallosapp over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-30840HIGH Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, there is a server-side request forgery vulnerability in notification testers. This is | Mar 7, 2026 | 8.8 | 31 | NO | NO |
CVE-2024-55372CRITICAL Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of th | Apr 16, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-55371CRITICAL Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZI | Apr 16, 2025 | 9.8 | 27 | NO | NO |
CVE-2026-33407CRITICAL Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, Wallos endpoints/logos/search.php accepts HTTP_PROXY and HTTPS_PROXY environment vari | Mar 24, 2026 | 9.1 | 26 | NO | NO |
CVE-2026-33399HIGH Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the SSRF fix applied in version 4.6.2 for CVE-2026-30839 and CVE-2026-30840 is incomp | Mar 24, 2026 | 7.7 | 26 | NO | NO |
CVE-2026-30828HIGH Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, the url parameter can be used to retrieve local system files. This issue has been pat | Mar 7, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-27479HIGH Wallos is an open-source, self-hostable personal subscription tracker. Versions 4.6.0 and below contain a Server-Side Request Forgery (SSRF) vulnerability in the subscription and p | Feb 21, 2026 | 7.7 | 23 | NO | NO |
CVE-2024-29320HIGH Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php. | Apr 30, 2024 | 8.1 | 22 | NO | NO |
CVE-2026-33417HIGH Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in Wallos never expire. The password_resets table includes a cr | Mar 24, 2026 | 7.1 | 21 | NO | NO |
CVE-2026-33401MEDIUM Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to no | Mar 24, 2026 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wallosapp.
Media articles that mention a CVE ID that affects a product developed by Wallosapp — matched by CVE ID, not by vendor name.