Halo

Halo

33 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 12.02.2026 00:00:00
  • Zuletzt bearbeitet 18.02.2026 15:45:23

An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint

Exploit
  • EPSS 0.03%
  • Veröffentlicht 28.12.2025 15:02:05
  • Zuletzt bearbeitet 24.02.2026 07:16:58

A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to information disclosure. The attack may be performed fr...

  • EPSS 0.02%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 18.09.2025 20:33:03

Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.

  • EPSS 0.02%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 18.09.2025 20:33:52

Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnerability is fixed in 2.20.13

  • EPSS 0.04%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 17.09.2025 19:34:21

halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.

Exploit
  • EPSS 1.02%
  • Veröffentlicht 25.04.2025 15:08:00
  • Zuletzt bearbeitet 03.02.2026 19:16:10

Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which ca...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 11.09.2024 15:15:17
  • Zuletzt bearbeitet 16.09.2024 16:28:45

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML...

Exploit
  • EPSS 0.46%
  • Veröffentlicht 02.09.2024 18:15:35
  • Zuletzt bearbeitet 16.09.2024 16:26:18

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML...

  • EPSS 0.2%
  • Veröffentlicht 28.03.2024 23:15:46
  • Zuletzt bearbeitet 28.03.2025 19:15:16

halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).

Exploit
  • EPSS 0.33%
  • Veröffentlicht 10.03.2023 16:15:11
  • Zuletzt bearbeitet 21.11.2024 07:52:24

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.