Horilla
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 26 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from December 4, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Horilla attendance approval endpoint is vulnerable to cross-site request forgery
Horilla: Authenticated RCE in Horilla List-View Export
Horilla: Reflected Cross-Site Scripting (XSS) in Employee Filter View
Horilla: Server-Side Template Injection (SSTI) in Mail Preview Endpoints Allows Authenticated Users to Disclose Password Hashes and Server Metadata
Horilla: Missing Authorization on Payroll Component Views Exposes Employee Salary Structures and Personal Loan Records (IDOR)
Horilla: Open Redirect via Unvalidated `next` Parameter in Notification Endpoints
Horilla: Unauthorized Helpdesk Attachment Access via Attachment ID Manipulation
Horilla: Unauthorized Document Overwrite via File Upload Endpoint
Horilla: Insecure Direct Object Reference at `/employee/view-file/<int:id>
horilla-opensource horilla Leads global.js cross site scripting
Monitor Horilla in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.