Halo

Halo

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.24%
  • Veröffentlicht 09.09.2025 00:00:00
  • Zuletzt bearbeitet 18.09.2025 20:33:03

Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 25.04.2025 15:08:00
  • Zuletzt bearbeitet 03.02.2026 19:16:10

Halo is an open source website building tool. Prior to version 2.20.13, a vulnerability in Halo allows attackers to bypass file type validation controls. This bypass enables the upload of malicious files including executables and HTML files, which ca...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 11.09.2024 15:15:17
  • Zuletzt bearbeitet 16.09.2024 16:28:45

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.19.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 02.09.2024 18:15:35
  • Zuletzt bearbeitet 16.09.2024 16:26:18

Halo is an open source website building tool. A security vulnerability has been identified in versions prior to 2.17.0 of the Halo project. This vulnerability allows an attacker to execute malicious scripts in the user's browser through specific HTML...

  • EPSS 0.31%
  • Veröffentlicht 28.03.2024 23:15:46
  • Zuletzt bearbeitet 28.03.2025 19:15:16

halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).

Exploit
  • EPSS 0.69%
  • Veröffentlicht 10.03.2023 16:15:11
  • Zuletzt bearbeitet 09.07.2026 01:18:12

An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.

Exploit
  • EPSS 16.27%
  • Veröffentlicht 27.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 07:07:22

Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.

Exploit
  • EPSS 17.11%
  • Veröffentlicht 27.06.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 07:07:22

Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.

Exploit
  • EPSS 0.87%
  • Veröffentlicht 05.04.2022 01:15:09
  • Zuletzt bearbeitet 21.11.2024 06:54:12

Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.

Exploit
  • EPSS 0.55%
  • Veröffentlicht 24.03.2022 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:29:33

In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.