Vulnerabilidades en ellite

27 resultados
Análisis Vexday

A Ellite apresenta 14 vulnerabilidades catalogadas, com 3 publicadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma vulnerabilidade está sob ataque ativo (KEV) e não há críticas registradas, o que reduz a urgência imediata. A fraqueza dominante (CWE-918 - Server-Side Request Forgery) representa um vetor de risco estrutural que merece remediação planejada.

CVE-2026-30828HIGHWallos: SSRF via url parameter leading to File TraversalEPSS 0.5%CVE-2026-30840HIGHWallos: Server-Side Request Forgery (SSRF) in Notification TestersEPSS 0.5%CVE-2026-33407HIGHWallos: SSRF via HTTP Proxy Environment VariableEPSS 0.4%CVE-2026-61639HIGHWallos: Zip Slip path traversal in database restore writes files to webrootEPSS 0.3%CVE-2026-54600HIGHWallos: Unauthenticated database replacement via import endpoint on fresh installEPSS 0.3%CVE-2026-30839MEDIUMWallos: SSRF via webhook test endpointEPSS 0.3%CVE-2026-54598HIGHMissing Authentication for Critical Function in wallosEPSS 0.3%CVE-2026-27479HIGHWallos: SSRF via Redirect Bypass in Logo/Icon URL FetchEPSS 0.3%CVE-2026-61640HIGHWallos: SSRF via OIDC Token/UserInfo URL ConfigurationEPSS 0.3%CVE-2026-61641HIGHWallos: OIDC account takeover via email-based account linking without `email_verified` checkEPSS 0.3%CVE-2026-30842MEDIUMWallos: Authenticated Missing Authorization Allows Deletion of Other Users’ Uploaded AvatarsEPSS 0.3%CVE-2026-61638HIGHWallos: SSRF via Test Email Notification - unvalidated SMTP host/portEPSS 0.3%CVE-2026-33401HIGHWallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.phpEPSS 0.3%CVE-2026-30841MEDIUMWallos: Reflected XSS via unescaped token and email parameters in passwordreset.phpEPSS 0.3%CVE-2026-33399HIGHWallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840EPSS 0.3%CVE-2026-33417MEDIUMWallos: Password Reset Tokens Never ExpireEPSS 0.3%CVE-2026-77348HIGHWallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`EPSS 0.2%CVE-2026-41688HIGHIncomplete fix for CVE-2026-33399: SSRF in WallosEPSS 0.2%CVE-2026-50198MEDIUMWallos: Cross-user subscription cost inference via replacement_subscription_idEPSS 0.2%CVE-2026-41687MEDIUMWallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline ChecksEPSS 0.2%