vciy

CVEs we hold for Ellite

Records whose assigning authority named Ellite as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-77353Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Exportellite Wallos
CVE-2026-77352Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)ellite Wallos
CVE-2026-77351Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settingsellite Wallos
CVE-2026-77348Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via…ellite Wallos
CVE-2026-61641Wallos: OIDC account takeover via email-based account linking without `email_verified` checkellite Wallos
CVE-2026-61640Wallos: SSRF via OIDC Token/UserInfo URL Configurationellite Wallos
CVE-2026-61639Wallos: Zip Slip path traversal in database restore writes files to webrootellite Wallos
CVE-2026-61638Wallos: SSRF via Test Email Notification - unvalidated SMTP host/portellite Wallos
CVE-2026-54600Wallos: Unauthenticated database replacement via import endpoint on fresh installellite Wallos
CVE-2026-54599Wallos: OIDC state parameter never validated — login CSRF / account takeoverellite Wallos
CVE-2026-54598Missing Authentication for Critical Function in wallosellite Wallos
CVE-2026-50199Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refreshellite Wallos
CVE-2026-50198Wallos: Cross-user subscription cost inference via replacement_subscription_idellite Wallos
CVE-2026-41689Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal servicesellite Wallos
CVE-2026-41688Incomplete fix for CVE-2026-33399: SSRF in Wallosellite Wallos
CVE-2026-41687Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checksellite Wallos
CVE-2026-33417Wallos: Password Reset Tokens Never Expireellite Wallos
CVE-2026-33407Wallos: SSRF via HTTP Proxy Environment Variableellite Wallos
CVE-2026-33401Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.phpellite Wallos
CVE-2026-33400Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpointellite Wallos
CVE-2026-33399Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840ellite Wallos
CVE-2026-30842Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatarsellite Wallos
CVE-2026-30841Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.phpellite Wallos
CVE-2026-30840Wallos: Server-Side Request Forgery (SSRF) in Notification Testersellite Wallos
CVE-2026-30839Wallos: SSRF via webhook test endpointellite Wallos
CVE-2026-30828Wallos: SSRF via url parameter leading to File Traversalellite Wallos
CVE-2026-27479Wallos: SSRF via Redirect Bypass in Logo/Icon URL Fetchellite Wallos

27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.