Qloapps
by Webkul
Source repositories
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-6173 | Med | 0.31 | 4.7 | 0.00 | Jun 17, 2025 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched… | ||
| CVE-2023-30256 | 0.09 | — | 0.09 | May 11, 2023 | Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file. | |||
| CVE-2023-36289 | 0.02 | — | 0.01 | Jun 23, 2023 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter. | |||
| CVE-2023-36287 | 0.02 | — | 0.01 | Jun 23, 2023 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter. | |||
| CVE-2023-36284 | 0.02 | — | 0.03 | Jun 23, 2023 | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database. | |||
| CVE-2024-40318 | 0.01 | — | 0.01 | Jul 25, 2024 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. | |||
| CVE-2025-10759 | 0.00 | — | 0.00 | Sep 21, 2025 | A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and… | |||
| CVE-2025-26058 | 0.00 | — | 0.00 | Feb 18, 2025 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. | |||
| CVE-2025-1155 | 0.00 | — | 0.00 | Feb 10, 2025 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is… | |||
| CVE-2025-1074 | 0.00 | — | 0.00 | Feb 6, 2025 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.… | |||
| CVE-2023-36235 | 0.00 | — | 0.01 | Jan 17, 2024 | An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. | |||
| CVE-2023-36288 | 0.00 | — | 0.00 | Jun 23, 2023 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter. |
- risk 0.31cvss 4.7epss 0.00
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched…
- CVE-2023-30256May 11, 2023risk 0.09cvss —epss 0.09
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
- CVE-2023-36289Jun 23, 2023risk 0.02cvss —epss 0.01
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
- CVE-2023-36287Jun 23, 2023risk 0.02cvss —epss 0.01
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
- CVE-2023-36284Jun 23, 2023risk 0.02cvss —epss 0.03
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
- CVE-2024-40318Jul 25, 2024risk 0.01cvss —epss 0.01
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2025-10759Sep 21, 2025risk 0.00cvss —epss 0.00
A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and…
- CVE-2025-26058Feb 18, 2025risk 0.00cvss —epss 0.00
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
- CVE-2025-1155Feb 10, 2025risk 0.00cvss —epss 0.00
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is…
- CVE-2025-1074Feb 6, 2025risk 0.00cvss —epss 0.00
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.…
- CVE-2023-36235Jan 17, 2024risk 0.00cvss —epss 0.01
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
- CVE-2023-36288Jun 23, 2023risk 0.00cvss —epss 0.00
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.