These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-91772 is a medium-severity open redirect vulnerability in Halo through version 2.26.1. The vulnerability exists in the anonymous thumbnail endpoint, which fails to validate the URI query parameter. This allows attackers to craft malicious links on the trusted Halo domain that redirect visitors to arbitrary external sites, enabling phishing attacks and abuse of redirect-based trust relationships.
CVE-2026-78971 is a vulnerability in Halo plugin management that allows users to install malicious plugins, potentially enabling attackers to execute commands with Halo process permissions. This vulnerability affects Halo versions <= 2.25.4 and could allow attackers to execute any command with Halo process permissions. Defenders should assess exposure and prioritize verification of plugin management confi [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4, located in the CorsConfigurer.java and CsrfConfigurer.java components. This allows a remote attacker to execute arbitrary code, with a CVSS score of 9.3 indicating CRITICAL severity. Administrators and users of affected versions should be aware and take necessary mitigation actions. The CVE record was published on [truncated]
A critical vulnerability in Halo 2.25.4 allows remote attackers to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginApplicationContextFactory components. Defenders should assess exposure, prioritize remediation, and verify affected versions to prevent exploitation and minimize potential damage. This vulnerability has a CVSS score of 9.8, indicating critical sever [truncated]
A path traversal vulnerability was detected in halo-dev halo up to 2.24.2. The vulnerability affects the function Download of the file MigrationEndpoint.java of the component Files Backup Endpoint. This could allow a remote attacker to perform path traversal. The exploit is now public and may be used. The CVSS score is 2, with a severity of LOW. Users of halo-dev halo up to 2.24.2 should assess the vulner [truncated]
A path traversal vulnerability was identified in Halo-Dev Halo up to 2.24.2. The vulnerability affects the Theme Installation component, specifically the ThemeUtils.unzipThemeTo function in ThemeUtils.java. The issue allows for path traversal through manipulation of the metadata.name argument. The attack may be launched remotely. The project closed the issue as 'duplicate' but did not reference any other [truncated]