Vendor CVEs
Webkul
All CVEs
76 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-6173 | Med | 0.31 | 4.7 | 0.01 | Jun 17, 2025 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched… | ||
| CVE-2024-45932 | Med | 0.31 | 4.8 | 0.00 | Oct 7, 2024 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. | ||
| CVE-2025-55744 | Med | 0.28 | 4.3 | 0.00 | Aug 21, 2025 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1. | ||
| CVE-2025-1155 | Med | 0.28 | 4.3 | 0.01 | Feb 10, 2025 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is… | ||
| CVE-2025-1074 | Med | 0.28 | 4.3 | 0.00 | Feb 6, 2025 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.… | ||
| CVE-2024-50637 | Med | 0.28 | 5.4 | 0.00 | Nov 6, 2024 | UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies. | ||
| CVE-2025-26058 | Med | 0.27 | 4.2 | 0.00 | Feb 18, 2025 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. | ||
| CVE-2025-62416 | Med | 0.26 | 5.1 | 0.00 | Oct 16, 2025 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with… | ||
| CVE-2026-19997 | Med | 0.24 | 4.7 | 0.00 | Aug 17, 2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to… | ||
| CVE-2026-19834 | Med | 0.24 | 4.7 | 0.00 | Aug 14, 2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can… | ||
| CVE-2023-36236 | Med | 0.24 | 4.8 | 0.01 | Jan 16, 2024 | Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. | ||
| CVE-2025-3568 | Low | 0.23 | 3.5 | 0.00 | Apr 14, 2025 | A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting.… | ||
| CVE-2026-75082 | Med | 0.21 | 4.3 | 0.00 | Aug 18, 2026 | A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It… | ||
| CVE-2026-75081 | Med | 0.21 | 4.3 | 0.00 | Aug 18, 2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed… | ||
| CVE-2026-19996 | Med | 0.21 | 4.3 | 0.00 | Aug 17, 2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack… | ||
| CVE-2026-19993 | Med | 0.21 | 4.3 | 0.00 | Aug 17, 2026 | A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The… | ||
| CVE-2026-19838 | Med | 0.21 | 4.3 | 0.00 | Aug 14, 2026 | A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is… | ||
| CVE-2026-19836 | Med | 0.21 | 4.3 | 0.00 | Aug 14, 2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization… | ||
| CVE-2026-19835 | Low | 0.18 | 3.8 | 0.00 | Aug 14, 2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is… | ||
| CVE-2026-19995 | Low | 0.16 | 3.5 | 0.00 | Aug 17, 2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the… | ||
| CVE-2023-2925 | Low | 0.16 | 2.4 | 0.01 | May 27, 2023 | A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site… | ||
| CVE-2026-19837 | Low | 0.11 | 2.7 | 0.00 | Aug 14, 2026 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched… | ||
| CVE-2010-1659 | 0.04 | — | 0.14 | May 3, 2010 | Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |||
| CVE-2023-36235 | Med | 0.00 | 6.5 | 0.01 | Jan 17, 2024 | An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. | ||
| CVE-2021-41924 | Med | 0.00 | 6.1 | 0.01 | Jun 21, 2022 | Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2019-14933 | Hig | 0.00 | 8.8 | 0.01 | Aug 11, 2019 | Bagisto 0.1.5 allows CSRF under /admin URIs. |
- risk 0.31cvss 4.7epss 0.01
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched…
- risk 0.31cvss 4.8epss 0.00
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
- risk 0.28cvss 4.3epss 0.00
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross site Request forgery (CSRF). This vulnerability is fixed in 0.2.1.
- risk 0.28cvss 4.3epss 0.01
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is…
- risk 0.28cvss 4.3epss 0.00
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.…
- risk 0.28cvss 5.4epss 0.00
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
- risk 0.27cvss 4.2epss 0.00
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
- risk 0.26cvss 5.1epss 0.00
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with…
- risk 0.24cvss 4.7epss 0.00
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to…
- risk 0.24cvss 4.7epss 0.00
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can…
- risk 0.24cvss 4.8epss 0.01
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
- risk 0.23cvss 3.5epss 0.00
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting.…
- risk 0.21cvss 4.3epss 0.00
A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It…
- risk 0.21cvss 4.3epss 0.00
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed…
- risk 0.21cvss 4.3epss 0.00
A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack…
- risk 0.21cvss 4.3epss 0.00
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The…
- risk 0.21cvss 4.3epss 0.00
A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is…
- risk 0.21cvss 4.3epss 0.00
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization…
- risk 0.18cvss 3.8epss 0.00
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is…
- risk 0.16cvss 3.5epss 0.00
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the…
- risk 0.16cvss 2.4epss 0.01
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site…
- risk 0.11cvss 2.7epss 0.00
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched…
- CVE-2010-1659May 3, 2010risk 0.04cvss —epss 0.14
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
- risk 0.00cvss 6.5epss 0.01
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
- risk 0.00cvss 6.1epss 0.01
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
- risk 0.00cvss 8.8epss 0.01
Bagisto 0.1.5 allows CSRF under /admin URIs.
Page 2 of 2