Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authenticated user to inject arbitrary JavaScript that executes when any user visits the Settings, Subscriptions, or Statistics pages. Combined with the wallos_login authentication cookie lacking the HttpOnly flag, this enables full session hijacking. This issue has been patched in version 4.7.0.
Metrics
Affected Vendors & Products
References
History
Thu, 26 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wallosapp
Wallosapp wallos |
|
| CPEs | cpe:2.3:a:wallosapp:wallos:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Wallosapp
Wallosapp wallos |
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ellite
Ellite wallos |
|
| Vendors & Products |
Ellite
Ellite wallos |
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.0, a stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint allows any authenticated user to inject arbitrary JavaScript that executes when any user visits the Settings, Subscriptions, or Statistics pages. Combined with the wallos_login authentication cookie lacking the HttpOnly flag, this enables full session hijacking. This issue has been patched in version 4.7.0. | |
| Title | Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-24T20:21:38.544Z
Reserved: 2026-03-19T17:02:34.170Z
Link: CVE-2026-33400
Updated: 2026-03-24T20:21:32.685Z
Status : Analyzed
Published: 2026-03-24T18:16:11.310
Modified: 2026-03-26T20:39:08.093
Link: CVE-2026-33400
No data.
OpenCVE Enrichment
Updated: 2026-03-25T20:49:37Z