alf.io
alfio-event- Product type
- Other
- Catalog vulnerabilities
- 9
Severity across 9 analyzed records
Verify to analyze this security profile
en
Severity across 9 analyzed records
Verify to analyze this security profile
As of 09/20/2026, within CyStack's analyzed data, alf.io has 1 security vulnerability published in the last 90 days. Of these, 1 is rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of alf.io and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-50165alf.io has Improper Access Control for Organization Owners that Exposes System Secrets | Exploitation statusNot known exploited | FixNot confirmed | Published09/09/2026 | SeverityHigh |
CVE-2026-41412alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script | Exploitation statusPublic exploit | FixNot confirmed | Published06/02/2026 | SeverityMedium |
CVE-2026-35482alf.io has an Authenticated RCE via Extension Script Sandbox Escape | Exploitation statusPublic exploit | FixNot confirmed | Published06/02/2026 | SeverityHigh |
CVE-2024-45300Bypassing promo code limitations with race conditions | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2024 | SeverityHigh |
CVE-2024-45299alf.io's preloaded data as json is not escaped correctly | Exploitation statusPublic exploit | FixNot confirmed | Published09/06/2024 | SeverityMedium |
CVE-2024-25634IDOR make user can read e-mail log sent by other events | Exploitation statusPublic exploit | FixNot confirmed | Published02/19/2024 | SeverityHigh |
CVE-2024-25635IDOR Vulnerability: Allowing Organization Owner to view the other Organizations API KEY and USERS | Exploitation statusPublic exploit | FixNot confirmed | Published02/19/2024 | SeverityHigh |
CVE-2024-25627Cross-Site Scripting (XSS) via File Upload in Alf.io | Exploitation statusPublic exploit | FixNot confirmed | Published02/16/2024 | SeverityLow |
CVE-2024-25628Insufficient Session Expiration in alf.io | Exploitation statusNot known exploited | FixNot confirmed | Published02/16/2024 | SeverityHigh |