High severity7.2NVD Advisory· Published Aug 25, 2026· Updated Aug 26, 2026
CVE-2026-75497
CVE-2026-75497
Description
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
3News mentions
1- Webkul QloApps: Three High-Severity Flaws Including RCE Disclosed TogetherVypr Intelligence · Aug 25, 2026