Halo

Halo

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 18.08.2026 00:00:00
  • Zuletzt bearbeitet 20.08.2026 17:19:31

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(), and org.springframework.util.FileSystemUtils.copyRecursively() components

  • EPSS 0.29%
  • Veröffentlicht 17.08.2026 00:00:00
  • Zuletzt bearbeitet 18.08.2026 12:19:28

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components

  • EPSS 0.21%
  • Veröffentlicht 30.04.2026 16:16:42
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /themes/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • EPSS 0.17%
  • Veröffentlicht 30.04.2026 16:16:42
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /themes/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • EPSS 0.14%
  • Veröffentlicht 30.04.2026 16:16:42
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /plugins/-/install-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

  • EPSS 0.17%
  • Veröffentlicht 30.04.2026 00:00:00
  • Zuletzt bearbeitet 30.04.2026 18:16:28

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Exploit
  • EPSS 0.44%
  • Veröffentlicht 12.02.2026 00:00:00
  • Zuletzt bearbeitet 18.02.2026 15:45:23

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

Exploit
  • EPSS 0.23%
  • Veröffentlicht 28.12.2025 15:02:05
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed fr...

  • EPSS 0.26%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 18.09.2025 20:33:52

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13

  • EPSS 0.37%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 17.09.2025 19:34:21

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.