Miguel Ribeiro
14 exploits
Active since Feb 2026
Wallos: SSRF CGNAT Bypass in subscription/payments Logo URL — is_cgnat_ip() Not Used in Inline Checks
CVSS 4.3
Incomplete fix for CVE-2026-33399: SSRF in Wallos
CVSS 7.7
Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php
CVSS 6.5
Wallos: Password Reset Tokens Never Expire
CVSS 6.5
Wallos: SSRF Bypass - Incomplete Fix for CVE-2026-30839/30840
CVSS 7.7
Wallos: Stored cross-site scripting (XSS) vulnerability in the payment method rename endpoint
CVSS 5.4
Wallos: Incomplete fix for CVE-2026-30840 - SSRF in AI and notification endpoints bypass ssrf_helper.php
CVSS 6.5
Wallos: SSRF via HTTP Proxy Environment Variable
CVSS 9.1
wallos < 4.6.2 - Server-Side Request Forgery via URL Parameter
CVSS 7.5
wallos < 4.6.2 - Server-Side Request Forgery via testwebhooknotifications.php
CVSS 4.3
wallos < 4.6.2 - Server-Side Request Forgery via Notification Tester
CVSS 8.8
wallos < 4.6.2 - Reflected Cross-Site Scripting via Password Reset Token and Email Parameters
CVSS 6.1
Wallos <4.6.2 - Privilege Escalation
CVSS 4.3
wallos < 4.6.1 - Server-Side Request Forgery via Logo Upload Redirect Bypass
CVSS 7.7