Halo

Halo

40 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 08.09.2026 00:00:00
  • Zuletzt bearbeitet 14.09.2026 15:17:07

In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions.

  • EPSS 0.29%
  • Veröffentlicht 18.08.2026 00:00:00
  • Zuletzt bearbeitet 31.08.2026 20:12:02

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components

  • EPSS 0.29%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 09.09.2026 16:04:24

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

  • EPSS 0.21%
  • Veröffentlicht 30.04.2026 16:16:42
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • EPSS 0.17%
  • Veröffentlicht 30.04.2026 16:16:42
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • EPSS 0.14%
  • Veröffentlicht 30.04.2026 16:16:42
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • EPSS 0.17%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 12.02.2026 00:00:00
  • Zuletzt bearbeitet 18.02.2026 15:45:23

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.12.2025 15:02:05
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed fr...

  • EPSS 0.24%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 18.09.2025 20:33:03

Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.