VYPR

Vendor CVEs

Webkul

All CVEs

76 total · sorted by risk
  • CVE-2026-38526CriApr 14, 2026
    risk 0.68cvss 9.9epss 0.02

    An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2025-29009CriJul 16, 2025
    risk 0.65cvss 10.0epss 0.01

    Unrestricted Upload of File with Dangerous Type vulnerability in Webkul Medical Prescription Attachment Plugin for WooCommerce medical-prescription-attachment-plugin-for-woocommerce allows Upload a Web Shell to a Web Server.This issue affects Medical Prescription Attachment…

  • CVE-2026-41452CriAug 3, 2026
    risk 0.64cvss 9.8epss 0.04

    Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to…

  • CVE-2025-67325CriJan 8, 2026
    risk 0.64cvss 9.8epss 0.01

    Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

  • CVE-2023-51210CriJan 23, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.

  • CVE-2024-46367CriSep 27, 2024
    risk 0.62cvss 9.6epss 0.01

    A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the…

  • CVE-2026-38529HigApr 14, 2026
    risk 0.57cvss 8.8epss 0.01

    A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.

  • CVE-2026-21450CriJan 2, 2026
    risk 0.57cvss 9.8epss 0.01

    Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

  • CVE-2026-21448CriJan 2, 2026
    risk 0.57cvss 9.8epss 0.01

    Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code…

  • CVE-2026-21446CriJan 2, 2026
    risk 0.57cvss 9.8epss 0.01

    Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any…

  • CVE-2024-46366HigSep 27, 2024
    risk 0.57cvss 8.8epss 0.01

    A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is…

  • CVE-2023-33570HigJun 28, 2023
    risk 0.57cvss 8.8epss 0.01

    Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

  • CVE-2019-16403HigSep 18, 2019
    risk 0.57cvss 8.8epss 0.01

    In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.

  • CVE-2023-39147HigAug 1, 2023
    risk 0.54cvss 7.8epss 0.01

    An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

  • CVE-2026-38532HigApr 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.

  • CVE-2026-38530HigApr 14, 2026
    risk 0.53cvss 8.1epss 0.00

    A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.

  • CVE-2026-79411HigSep 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update,…

  • CVE-2026-21449HigJan 2, 2026
    risk 0.50cvss 8.8epss 0.01

    Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.

  • CVE-2025-55745HigAug 22, 2025
    risk 0.50cvss 8.8epss 0.01

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formula injection, in the Quick Export feature. This vulnerability allows attackers to inject malicious…

  • CVE-2025-55743HigAug 21, 2025
    risk 0.50cvss 8.8epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the…

  • CVE-2023-36237HigFeb 26, 2024
    risk 0.50cvss 8.8epss 0.00

    Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

  • CVE-2023-36284HigJun 23, 2023
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.

  • CVE-2026-21451HigJan 2, 2026
    risk 0.48cvss 8.4epss 0.01

    Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `` tags, the filtering can be bypassed by…

  • CVE-2025-60880HigOct 10, 2025
    risk 0.47cvss 8.3epss 0.00

    An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute…

  • CVE-2024-40318HigJul 25, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2026-79410HigSep 15, 2026
    risk 0.46cvss 8.1epss 0.00

    Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

  • CVE-2025-55741HigAug 22, 2025
    risk 0.46cvss 8.1epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these…

  • CVE-2025-55742HigAug 21, 2025
    risk 0.45cvss 8.0epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via SVG MIME/sanitizer bypass in the /admin/settings/users/create endpoint. This vulnerability is fixed…

  • CVE-2025-62417HigOct 16, 2025
    risk 0.44cvss 7.8epss 0.00

    Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as…

  • CVE-2023-30256MedMay 11, 2023
    risk 0.43cvss 6.1epss 0.09

    Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.

  • CVE-2025-56426MedOct 9, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.

  • CVE-2026-75498HigAug 25, 2026
    risk 0.40cvss 7.2epss 0.01

    Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c.

  • CVE-2026-75497HigAug 25, 2026
    risk 0.40cvss 7.2epss 0.01

    Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.

  • CVE-2026-75496HigAug 25, 2026
    risk 0.40cvss 7.2epss 0.01

    Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution.…

  • CVE-2025-40675MedJun 9, 2025
    risk 0.40cvss 6.1epss 0.00

    A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can…

  • CVE-2023-36287MedJun 23, 2023
    risk 0.40cvss 6.1epss 0.01

    An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.

  • CVE-2023-36289MedJun 23, 2023
    risk 0.40cvss 6.1epss 0.01

    An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.

  • CVE-2026-21447HigJan 2, 2026
    risk 0.39cvss 7.1epss 0.00

    Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by…

  • CVE-2025-62418MedOct 16, 2025
    risk 0.38cvss 6.9epss 0.00

    Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malicious code executes in the…

  • CVE-2025-62415MedOct 16, 2025
    risk 0.38cvss 6.9epss 0.00

    Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing embedded JavaScript. When viewed, the malicious code executes in…

  • CVE-2025-62414MedOct 16, 2025
    risk 0.38cvss 6.9epss 0.00

    Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An attacker with access to the admin create-customer form can inject malicious JavaScript payloads…

  • CVE-2026-79409MedSep 15, 2026
    risk 0.35cvss 6.5epss 0.00

    An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

  • CVE-2021-41074MedJan 12, 2026
    risk 0.35cvss 5.4epss 0.00

    A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

  • CVE-2024-52305MedNov 13, 2024
    risk 0.35cvss 6.5epss 0.00

    UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG…

  • CVE-2023-36238MedMar 13, 2024
    risk 0.35cvss 6.5epss 0.01

    Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

  • CVE-2024-27499MedMar 1, 2024
    risk 0.35cvss 6.5epss 0.01

    Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

  • CVE-2023-37636MedOct 23, 2023
    risk 0.35cvss 5.4epss 0.00

    A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.

  • CVE-2023-36288MedJun 23, 2023
    risk 0.35cvss 5.4epss 0.00

    An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.

  • CVE-2026-19994MedAug 17, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization…

  • CVE-2025-10759MedSep 21, 2025
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and…

Page 1 of 2