← Back

Webkul

webkul

55 CVEs • 8 products

Products (8)

Click to collapse
Toggle
Bagisto
bagisto
Qloapps
qloapps
Krayin Crm
krayin_crm
Unopim
unopim
Uvdesk
uvdesk
Krayin
krayin
Bundle Product
bundle_product

CVEs (55)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Webkul
1Qloapps
Jun 17, 2026
Jan 17, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
1Webkul
1Bagisto
Jun 17, 2026
Jan 16, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
1Webkul
1Uvdesk
Jun 17, 2026
Oct 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket...Show more
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.Show less
1Webkul
1Uvdesk
Jun 17, 2026
Aug 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
1Webkul
1Bagisto
Jun 17, 2026
Jun 28, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
1Webkul
1Qloapps
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
1Webkul
1Qloapps
Jun 17, 2026
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mecha...Show more
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.Show less
1Webkul
1Qloapps
Jun 17, 2026
Jun 23, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
1Webkul
1Qloapps
Jun 17, 2026
Jun 23, 2023
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
1Webkul
1Krayin Crm
Jun 17, 2026
May 27, 2023
N/A· v4
5.4 MEDIUM· v3
3.3 LOW· v2
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulatio...Show more
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230079. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Webkul
1Qloapps
Jun 17, 2026
May 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
1Webkul
1Krayin
Jun 17, 2026
Jun 21, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
1Webkul
1Bagisto
Jun 17, 2026
Sep 18, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
1Webkul
1Bagisto
Jun 17, 2026
Aug 11, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Bagisto 0.1.5 allows CSRF under /admin URIs.
1Webkul
1Com Ultimateportfolio
Apr 29, 2026
May 3, 2010
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.