← Back

Halo

halo

Vendor: Fit2cloud • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fit2cloud
1Halo
Jun 17, 2026
Dec 6, 2025
2.1 LOW· v4
6.5 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the...Show more
A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Fit2cloud
1Halo
Jun 17, 2026
Apr 22, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
Halo-1.5.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via \admin\index.html#/system/tools.
1Fit2cloud
1Halo
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascr...Show more
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the profile image. An authenticated attacker can upload a carefully crafted SVG file that will trigger arbitrary javascript to run on a victim’s browser.Show less
1Fit2cloud
1Halo
Jun 17, 2026
Jan 13, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server...Show more
In Halo, versions v1.0.0 to v1.4.17 (latest) are vulnerable to Stored Cross-Site Scripting (XSS) in the article title. An authenticated attacker can inject arbitrary javascript code that will execute on a victim’s server.Show less