Package impact

golang Go / github.com/hahwul/dalfox/v2

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-45087 critical 10.0 10.0 22h ago Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started in REST API server mode (dalfox server), the server binds to 0.0.0.0:6664 by de… golang
CVE-2026-45089 high 8.2 8.2 22h ago Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option golang
CVE-2026-45088 high 7.5 7.5 22h ago Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file` golang
CVE-2026-45090 high 7.5 7.5 22h ago Dalfox has an Unauthenticated Remote DoS via Closed-Channel Write in `ParameterAnalysis` (server mode) golang