Known Vulnerabilities for Halo by Fit2cloud
Listed below are 4 of the newest known vulnerabilities associated with "Halo" by "Fit2cloud".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-97182 json | A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the file ... | Not Provided | 2026-09-24 | 2026-09-24 |
| CVE-2026-91772 json | Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate the ur... | Not Provided | 2026-09-15 | 2026-09-16 |
| CVE-2026-78971 json | In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers ... | Not Provided | 2026-09-08 | 2026-09-14 |
| CVE-2026-67921 json | Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the ... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-67920 json | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServi... | Not Provided | 2026-08-18 | 2026-08-20 |
| CVE-2026-67919 json | An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method... | Not Provided | 2026-08-17 | 2026-08-18 |
| CVE-2026-16088 json | A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of the fi... | Not Provided | 2026-07-18 | 2026-07-20 |
| CVE-2025-14117 json | Not Provided | 2025-12-06 | 2026-04-29 | |
| CVE-2022-28074 json | Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools. | 4.8 - MEDIUM | 2022-04-22 | 2022-05-03 |
| CVE-2022-22124 json | In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An aut... | 5.4 - MEDIUM | 2022-01-13 | 2022-01-14 |