{"schema_version":1,"title":"Ellite Wallos vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in Ellite Wallos: 0 in the last 7 days and 13 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77353, was published on 31 August 2026.","url":"https://junglewise.ai/threats/technologies/wallos","json_url":"https://junglewise.ai/threats/technologies/wallos.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/wallos","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":4,"all_time":14,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":13,"last_90_days":13,"last_365_days":14},"latest":[{"cve":"CVE-2026-77353","cvss":4.6,"epss":0.0029,"slug":"cve-2026-77353-wallos-crlf-injection-in-icalendar-export","title":"Wallos CRLF injection in iCalendar export","severity":"medium","exploited":false,"published_at":"2026-08-31T22:17:20.743+00:00","url":"https://junglewise.ai/threats/cve-2026-77353-wallos-crlf-injection-in-icalendar-export"},{"cve":"CVE-2026-77352","cvss":4.3,"epss":0.0033,"slug":"cve-2026-77352-wallos-ssrf-in-smtp-host-configuration","title":"Wallos SSRF in SMTP host configuration","severity":"medium","exploited":false,"published_at":"2026-08-31T22:17:20.607+00:00","url":"https://junglewise.ai/threats/cve-2026-77352-wallos-ssrf-in-smtp-host-configuration"},{"cve":"CVE-2026-77351","cvss":3.5,"epss":0.0029,"slug":"cve-2026-77351-wallos-ssrf-in-email-notification-settings","title":"Wallos SSRF in email notification settings","severity":"low","exploited":false,"published_at":"2026-08-31T22:17:20.467+00:00","url":"https://junglewise.ai/threats/cve-2026-77351-wallos-ssrf-in-email-notification-settings"},{"cve":"CVE-2026-77348","cvss":8.2,"epss":0.0043,"slug":"cve-2026-77348-wallos-ssrf-via-http-proxy-environment-variable-in-payments","title":"Wallos SSRF via HTTP proxy environment variable in payments search","severity":"high","exploited":false,"published_at":"2026-08-31T22:17:20.317+00:00","url":"https://junglewise.ai/threats/cve-2026-77348-wallos-ssrf-via-http-proxy-environment-variable-in-payments"},{"cve":"CVE-2026-61641","cvss":8.1,"epss":0.0053,"slug":"cve-2026-61641-wallos-oidc-account-takeover-via-unverified-email-linking","title":"Wallos OIDC account takeover via unverified email linking","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:17.373+00:00","url":"https://junglewise.ai/threats/cve-2026-61641-wallos-oidc-account-takeover-via-unverified-email-linking"},{"cve":"CVE-2026-61640","epss":0.0054,"slug":"cve-2026-61640-wallos-ssrf-in-oidc-configuration","title":"Wallos SSRF in OIDC configuration","severity":"info","exploited":false,"published_at":"2026-08-31T21:17:17.243+00:00","url":"https://junglewise.ai/threats/cve-2026-61640-wallos-ssrf-in-oidc-configuration"},{"cve":"CVE-2026-61639","cvss":8.8,"epss":0.0051,"slug":"cve-2026-61639-wallos-path-traversal-in-database-restore","title":"Wallos path traversal in database restore","severity":"info","exploited":false,"published_at":"2026-08-31T21:17:17.103+00:00","url":"https://junglewise.ai/threats/cve-2026-61639-wallos-path-traversal-in-database-restore"},{"cve":"CVE-2026-61638","epss":0.005,"slug":"cve-2026-61638-wallos-ssrf-in-test-email-notification","title":"Wallos SSRF in test email notification","severity":"info","exploited":false,"published_at":"2026-08-31T21:17:16.95+00:00","url":"https://junglewise.ai/threats/cve-2026-61638-wallos-ssrf-in-test-email-notification"},{"cve":"CVE-2026-54600","cvss":7.5,"epss":0.0058,"slug":"cve-2026-54600-wallos-unauthenticated-database-replacement-on-fresh-install","title":"Wallos unauthenticated database replacement on fresh install","severity":"info","exploited":false,"published_at":"2026-08-31T21:17:10.267+00:00","url":"https://junglewise.ai/threats/cve-2026-54600-wallos-unauthenticated-database-replacement-on-fresh-install"},{"cve":"CVE-2026-54599","epss":0.0022,"slug":"cve-2026-54599-wallos-oidc-state-validation-missing-in-login-csrf","title":"Wallos OIDC state validation missing in login CSRF","severity":"info","exploited":false,"published_at":"2026-08-31T21:17:10.063+00:00","url":"https://junglewise.ai/threats/cve-2026-54599-wallos-oidc-state-validation-missing-in-login-csrf"},{"cve":"CVE-2026-54598","cvss":7.5,"epss":0.0046,"slug":"cve-2026-54598-wallos-unauthenticated-database-migration-execution","title":"Wallos unauthenticated database migration execution","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:09.843+00:00","url":"https://junglewise.ai/threats/cve-2026-54598-wallos-unauthenticated-database-migration-execution"},{"cve":"CVE-2026-50199","cvss":4.3,"epss":0.0026,"slug":"cve-2026-50199-wallos-incorrect-authorization-in-exchange-rate-refresh","title":"Wallos incorrect authorization in exchange-rate refresh","severity":"medium","exploited":false,"published_at":"2026-08-31T21:17:08.847+00:00","url":"https://junglewise.ai/threats/cve-2026-50199-wallos-incorrect-authorization-in-exchange-rate-refresh"},{"cve":"CVE-2026-50198","cvss":4.3,"epss":0.0029,"slug":"cve-2026-50198-wallos-cross-user-subscription-cost-inference-via-replacement","title":"Wallos cross-user subscription cost inference via replacement_subscription_id","severity":"medium","exploited":false,"published_at":"2026-08-31T21:17:08.7+00:00","url":"https://junglewise.ai/threats/cve-2026-50198-wallos-cross-user-subscription-cost-inference-via-replacement"},{"cve":"CVE-2025-60535","cvss":7.3,"epss":0.0017,"slug":"cve-2025-60535-wallos-csrf-in-currency-and-category-endpoints","title":"Wallos CSRF in currency and category endpoints","severity":"high","exploited":false,"published_at":"2025-10-14T17:16:14.203+00:00","url":"https://junglewise.ai/threats/cve-2025-60535-wallos-csrf-in-currency-and-category-endpoints"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":13},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Ellite Wallos","slug":"wallos","vendor":{"name":"Ellite","slug":"ellite","url":"https://junglewise.ai/threats/vendors/ellite"},"aliases":[],"category":"web-application","homepage":"https://wallosapp.com/","repo_url":"https://github.com/ellite/Wallos","description":"A web-based application for managing personal finances and subscriptions.","url":"https://junglewise.ai/threats/technologies/wallos"},"most_severe":[{"cve":"CVE-2026-77348","cvss":8.2,"epss":0.0043,"slug":"cve-2026-77348-wallos-ssrf-via-http-proxy-environment-variable-in-payments","title":"Wallos SSRF via HTTP proxy environment variable in payments search","severity":"high","exploited":false,"published_at":"2026-08-31T22:17:20.317+00:00","url":"https://junglewise.ai/threats/cve-2026-77348-wallos-ssrf-via-http-proxy-environment-variable-in-payments"},{"cve":"CVE-2026-61641","cvss":8.1,"epss":0.0053,"slug":"cve-2026-61641-wallos-oidc-account-takeover-via-unverified-email-linking","title":"Wallos OIDC account takeover via unverified email linking","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:17.373+00:00","url":"https://junglewise.ai/threats/cve-2026-61641-wallos-oidc-account-takeover-via-unverified-email-linking"},{"cve":"CVE-2026-54598","cvss":7.5,"epss":0.0046,"slug":"cve-2026-54598-wallos-unauthenticated-database-migration-execution","title":"Wallos unauthenticated database migration execution","severity":"high","exploited":false,"published_at":"2026-08-31T21:17:09.843+00:00","url":"https://junglewise.ai/threats/cve-2026-54598-wallos-unauthenticated-database-migration-execution"},{"cve":"CVE-2025-60535","cvss":7.3,"epss":0.0017,"slug":"cve-2025-60535-wallos-csrf-in-currency-and-category-endpoints","title":"Wallos CSRF in currency and category endpoints","severity":"high","exploited":false,"published_at":"2025-10-14T17:16:14.203+00:00","url":"https://junglewise.ai/threats/cve-2025-60535-wallos-csrf-in-currency-and-category-endpoints"},{"cve":"CVE-2026-77353","cvss":4.6,"epss":0.0029,"slug":"cve-2026-77353-wallos-crlf-injection-in-icalendar-export","title":"Wallos CRLF injection in iCalendar export","severity":"medium","exploited":false,"published_at":"2026-08-31T22:17:20.743+00:00","url":"https://junglewise.ai/threats/cve-2026-77353-wallos-crlf-injection-in-icalendar-export"},{"cve":"CVE-2026-77352","cvss":4.3,"epss":0.0033,"slug":"cve-2026-77352-wallos-ssrf-in-smtp-host-configuration","title":"Wallos SSRF in SMTP host configuration","severity":"medium","exploited":false,"published_at":"2026-08-31T22:17:20.607+00:00","url":"https://junglewise.ai/threats/cve-2026-77352-wallos-ssrf-in-smtp-host-configuration"},{"cve":"CVE-2026-50198","cvss":4.3,"epss":0.0029,"slug":"cve-2026-50198-wallos-cross-user-subscription-cost-inference-via-replacement","title":"Wallos cross-user subscription cost inference via replacement_subscription_id","severity":"medium","exploited":false,"published_at":"2026-08-31T21:17:08.7+00:00","url":"https://junglewise.ai/threats/cve-2026-50198-wallos-cross-user-subscription-cost-inference-via-replacement"},{"cve":"CVE-2026-50199","cvss":4.3,"epss":0.0026,"slug":"cve-2026-50199-wallos-incorrect-authorization-in-exchange-rate-refresh","title":"Wallos incorrect authorization in exchange-rate refresh","severity":"medium","exploited":false,"published_at":"2026-08-31T21:17:08.847+00:00","url":"https://junglewise.ai/threats/cve-2026-50199-wallos-incorrect-authorization-in-exchange-rate-refresh"},{"cve":"CVE-2026-77351","cvss":3.5,"epss":0.0029,"slug":"cve-2026-77351-wallos-ssrf-in-email-notification-settings","title":"Wallos SSRF in email notification settings","severity":"low","exploited":false,"published_at":"2026-08-31T22:17:20.467+00:00","url":"https://junglewise.ai/threats/cve-2026-77351-wallos-ssrf-in-email-notification-settings"},{"cve":"CVE-2026-61639","cvss":8.8,"epss":0.0051,"slug":"cve-2026-61639-wallos-path-traversal-in-database-restore","title":"Wallos path traversal in database restore","severity":"info","exploited":false,"published_at":"2026-08-31T21:17:17.103+00:00","url":"https://junglewise.ai/threats/cve-2026-61639-wallos-path-traversal-in-database-restore"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}