CVEs we hold for Ellite
Records whose assigning authority named Ellite as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-77352Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)ellite Wallos
CVE-2026-77351Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settingsellite Wallos
CVE-2026-77348Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via…ellite Wallos
CVE-2026-61641Wallos: OIDC account takeover via email-based account linking without `email_verified` checkellite Wallos
CVE-2026-61639Wallos: Zip Slip path traversal in database restore writes files to webrootellite Wallos
CVE-2026-54600Wallos: Unauthenticated database replacement via import endpoint on fresh installellite Wallos
CVE-2026-54599Wallos: OIDC state parameter never validated — login CSRF / account takeoverellite Wallos
CVE-2026-50199Wallos: Cross-user Fixer/API Layer credential consumption in exchange-rate refreshellite Wallos
CVE-2026-50198Wallos: Cross-user subscription cost inference via replacement_subscription_idellite Wallos
CVE-2026-41689Wallos: Shared local webhook allowlist lets low-privilege users send arbitrary requests to allowlisted internal servicesellite Wallos
CVE-2026-41687Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checksellite Wallos
CVE-2026-33401Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.phpellite Wallos
CVE-2026-33400Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpointellite Wallos
CVE-2026-30842Wallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded Avatarsellite Wallos
CVE-2026-30841Wallos: Reflected XSS via unescaped token and email parameters in passwordreset.phpellite Wallos
27 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.