CVE-2026-30841: Wallosapp Wallos
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.6.2, passwordreset.php outputs $_GET["token"] and $_GET["email"] directly into HTML input value attributes using <?= $token ?> and <?= $email ?> without calling htmlspecialchars(). This allows reflected XSS by breaking out of the attribute context. This issue has been patched in version 4.6.2.
Affected products
- Wallosapp Wallos: before 4.6.2 (fixed in 4.6.2)
Published 2026-03-07. Last modified 2026-06-17.