Wallos
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 22 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from February 23, 2024 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)
Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`
Wallos: SSRF via Test Email Notification - unvalidated SMTP host/port
Wallos: Unauthenticated database replacement via import endpoint on fresh install
Wallos: OIDC state parameter never validated — login CSRF / account takeover
Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refresh
Wallos: Cross-user subscription cost inference via replacement_subscription_id
Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal services
Incomplete fix for CVE-2026-33399: SSRF in Wallos
Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks
Monitor Wallos in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.