hallowelt CVE Vulnerabilities & Metrics

Focus on hallowelt vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About hallowelt Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with hallowelt. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total hallowelt CVEs: 11
Earliest CVE date: 22 Jul 2022, 16:15 UTC
Latest CVE date: 30 Oct 2023, 11:15 UTC

Latest CVE reference: CVE-2023-42431

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical hallowelt CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 0.0

Max CVSS: 0

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 11
4.0-6.9 0
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS hallowelt CVEs

These are the five CVEs with the highest CVSS scores for hallowelt, sorted by severity first and recency.

All CVEs for hallowelt

CVE-2023-42431 hallowelt vulnerability CVSS: 0 30 Oct 2023, 11:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context.

CVE-2022-42001 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceBookshelf extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the book navigation.

CVE-2022-42000 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceSocialProfile extension of BlueSpice allows user with comment permissions to inject arbitrary HTML into the comment section of a wikipage.

CVE-2022-41814 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceFoundation extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the history view of a wikipage.

CVE-2022-41789 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows logged in user with edit permissions to inject arbitrary HTML into the default page header of a wikipage.

CVE-2022-41611 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceDiscovery skin of BlueSpice allows user with admin privileges to inject arbitrary HTML into the main navigation of the application.

CVE-2022-3958 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceUserSidebar extension of BlueSpice allows user with regular account and edit permissions to inject arbitrary HTML into the personal menu navigation of their own and other users. This allows for targeted attacks.

CVE-2022-3895 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Some UI elements of the Common User Interface Component are not properly sanitizing output and therefore prone to output arbitrary HTML (XSS).

CVE-2022-3893 hallowelt vulnerability CVSS: 0 15 Nov 2022, 15:15 UTC

Cross-site Scripting (XSS) vulnerability in BlueSpiceCustomMenu extension of BlueSpice allows user with admin permissions to inject arbitrary HTML into the custom menu navigation of the application.

CVE-2022-2511 hallowelt vulnerability CVSS: 0 22 Jul 2022, 16:15 UTC

Cross-site Scripting (XSS) vulnerability in the "commonuserinterface" component of BlueSpice allows an attacker to inject arbitrary HTML into a page using the title parameter of the call URL.

CVE-2022-2510 hallowelt vulnerability CVSS: 0 22 Jul 2022, 16:15 UTC

Cross-site Scripting (XSS) vulnerability in "Extension:ExtendedSearch" of Hallo Welt! GmbH BlueSpice allows attacker to inject arbitrary HTML (XSS) on page "Special:SearchCenter", using the search term in the URL.