CVE-2024-29320: Wallosapp Wallos

High severity, CVSS 8.1. EPSS: 0.7% chance of exploitation in the next 30 days.

Wallos before 1.15.3 is vulnerable to SQL Injection via the category and payment parameters to /subscriptions/get.php.

Affected products

  • Wallosapp Wallos: before 1.15.3 (fixed in 1.15.3)

Published 2024-04-30. Last modified 2026-06-17.