Vulnerabilities > Halo > Halo > 1.6.0

DATE CVE VULNERABILITY TITLE RISK
2024-09-11 CVE-2024-43793 Cross-site Scripting vulnerability in Halo
Halo is an open source website building tool.
network
low complexity
halo CWE-79
6.4
2024-09-02 CVE-2024-43792 Cross-site Scripting vulnerability in Halo
Halo is an open source website building tool.
network
low complexity
halo CWE-79
6.1
2024-03-28 CVE-2023-33528 Cross-site Scripting vulnerability in Halo 1.6.0
halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).
network
low complexity
halo CWE-79
6.1
2023-03-10 CVE-2023-27164 Unrestricted Upload of File with Dangerous Type vulnerability in Halo
An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.
network
low complexity
halo CWE-434
4.8