VYPR
Vendor

Webkul

Products
5
CVEs
25
Across products
25
Status
Private

Products

5

Recent CVEs

25
View all 25 CVEs →
  • CVE-2025-29009CriJul 16, 2025
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment…

  • CVE-2026-38526CriApr 14, 2026
    risk 0.64cvss 9.9epss 0.01

    An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2026-38529HigApr 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.

  • CVE-2026-38532HigApr 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.

  • CVE-2026-38530HigApr 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.

  • CVE-2025-6173MedJun 17, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched…

  • CVE-2023-30256May 11, 2023
    risk 0.09cvss epss 0.09

    Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

  • CVE-2010-1659May 3, 2010
    risk 0.04cvss epss 0.14

    Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.

  • CVE-2023-36289Jun 23, 2023
    risk 0.02cvss epss 0.01

    An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.

  • CVE-2023-36287Jun 23, 2023
    risk 0.02cvss epss 0.01

    An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.

  • CVE-2023-36284Jun 23, 2023
    risk 0.02cvss epss 0.03

    An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

  • CVE-2024-40318Jul 25, 2024
    risk 0.01cvss epss 0.01

    An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2021-41074Jan 12, 2026
    risk 0.00cvss epss 0.00

    A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

  • CVE-2025-67325Jan 8, 2026
    risk 0.00cvss epss 0.01

    Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

  • CVE-2025-10759Sep 21, 2025
    risk 0.00cvss epss 0.00

    A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and…

  • CVE-2025-3568Apr 14, 2025
    risk 0.00cvss epss 0.00

    A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting.…

  • CVE-2025-26058Feb 18, 2025
    risk 0.00cvss epss 0.00

    Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.

  • CVE-2025-1155Feb 10, 2025
    risk 0.00cvss epss 0.00

    A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is…

  • CVE-2025-1074Feb 6, 2025
    risk 0.00cvss epss 0.00

    A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.…

  • CVE-2024-46366Sep 27, 2024
    risk 0.00cvss epss 0.00

    A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is…