CVE Tools

Halo

15 CVEs tracked since 2020. Since Sep 2020, none of them reached CISA KEV.

Halo CVEs per month

Sep 2020 to Jan 2022. Point at a month, or focus the strip and use the arrow keys.
Halo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-0960
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-0760
2021-08null or fewer
2021-09null or fewer
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-0130

Products

The products that kept showing up in Halo's monthly top three, with their CVEs summed over those months.

  1. Halo153 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Halo.

  1. CVE-2025-70886An issue in halo v.2.22.4 and before allows a remote attacker to cause a denial of service via a crafted payload to the public comment submission endpoint7.5
  2. CVE-2025-15141Halo Configuration actuator information disclosure3.1
  3. CVE-2025-44595Halo v2.20.17 and before is vulnerable to Cross Site Scripting (XSS) in /halo_host/archives/{name}.6.1
  4. CVE-2025-44594halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/attachments/-/upload-from-url.9.1
  5. CVE-2025-44593Halo prior to 2.20.13 allows bypassing file type detection and uploading malicious files such as .exe and .html files. Specifically, .html files can trigger stored XSS vulnerabilities. This vulnera...6.1
  6. CVE-2024-56156Halo Vulnerable to Stored XSS and RCE via File Upload Bypass9.0
  7. CVE-2024-43793Halo's editor has a stored XSS vulnerability6.3
  8. CVE-2024-43792Halo's editor has a stored Cross-Site Scripting vulnerability6.3
  9. CVE-2023-33528halo v1.6.0 is vulnerable to Cross Site Scripting (XSS).6.1
  10. CVE-2023-27164An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file.4.8
  11. CVE-2022-32995Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function.9.8
  12. CVE-2022-32994Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachments/upload.9.8
  13. CVE-2022-26619Halo Blog CMS v1.4.17 was discovered to allow attackers to upload arbitrary files via the Attachment Upload function.7.5
  14. CVE-2021-43659In halo 1.4.14, the function point of uploading the avatar, any file can be uploaded, such as uploading an HTML file, which will cause a stored XSS vulnerability.5.4
  15. CVE-2022-22125Halo CMS - Stored Cross-Site Scripting (XSS) in Article's Tag4.8

The record

Peak rank
#66 in Sep 2020
Busiest month shown
Sep 2020, 6 CVEs
Months with a KEV entry
0 since Sep 2020
Monthly snapshots
3 since 2020
Halo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store