Skip to content
Noroxi

Webkul records

57 published records for vendor webkul.

All records

57 records
  • Unauthenticated Remote Code Execution in UvDesk Community

    CriticalCVSS 10.0No exploitEPSS 1%

    webkul software · uvdesk communityApr 25, 2024

  • SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters

    CriticalCVSS 9.8No exploitEPSS 1%

    webkul · bundle productJan 23, 2024

  • Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achiev

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    webkul · qloappsJan 8, 2026

  • A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by

    CriticalCVSS 9.6No exploitEPSS 1%

    webkul · krayin crmSep 27, 2024

  • In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can als

    HighCVSS 8.8No exploitEPSS 1%

    webkul · bagistoSep 18, 2019

  • Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

    HighCVSS 8.8No exploitEPSS 1%

    webkul · bagistoJun 28, 2023

  • Bagisto has Normal & Blind SSTI from low-privilege user when ordering product

    HighCVSS 8.9No exploitEPSS 1%

    webkul · bagistoJan 2, 2026

  • A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att

    HighCVSS 8.8No exploitEPSS 1%

    webkul · krayin crmApr 14, 2026

  • Bagisto Missing Authentication on Installer API Endpoints

    HighCVSS 8.8No exploitEPSS 1%

    webkul · bagistoJan 2, 2026

  • Bagisto 0.1.5 allows CSRF under /admin URIs.

    HighCVSS 8.8No exploitEPSS 1%

    webkul · bagistoAug 11, 2019

  • A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side te

    HighCVSS 8.8No exploitEPSS 1%

    webkul · krayin crmSep 27, 2024

  • Joomla! Component Ajax Quiz 1.8 SQL Injection

    HighCVSS 8.8No exploitEPSS 0%

    webkul · ajax quizJun 19, 2026

  • Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

    HighCVSS 8.8No exploitEPSS 0%

    webkul · bagistoFeb 26, 2024

  • An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a

    HighCVSS 8.3Proof of conceptEPSS 0%

    webkul · bagistoOct 10, 2025

  • unopim/unopim allows unauthorized product deletion via mass-delete endpoint

    HighCVSS 8.1No exploitEPSS 0%

    webkul · unopimAug 22, 2025

  • A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenti

    HighCVSS 8.1No exploitEPSS 0%

    webkul · krayin crmApr 14, 2026

  • A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authentic

    HighCVSS 8.1No exploitEPSS 0%

    webkul · krayin crmApr 14, 2026

  • An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remo

    HighCVSS 7.5Proof of conceptEPSS 3%

    webkul · qloappsJun 23, 2023

  • An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

    HighCVSS 7.8Proof of conceptEPSS 1%

    webkul · uvdeskAug 1, 2023

  • Bagisto has SSTI in parameter that can lead to RCE

    HighCVSS 7.3No exploitEPSS 1%

    webkul · bagistoJan 2, 2026

  • Bagisto has SSTI via first and last name from low-privilege user (not admin)

    HighCVSS 7.4No exploitEPSS 1%

    webkul · bagistoJan 2, 2026

  • UnoPim vulnerable to remote code execution through Arbitrary File upload

    HighCVSS 7.3No exploitEPSS 0%

    webkul · unopimAug 21, 2025

  • An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

    HighCVSS 7.2Proof of conceptEPSS 1%

    webkul · qloappsJul 25, 2024

  • bagisto - CSV Formula Injection in Create New Product

    HighCVSS 7.1No exploitEPSS 0%

    webkul · bagistoOct 16, 2025

  • Bagisto has IDOR in Customer Order Reorder Functionality

    HighCVSS 7.1No exploitEPSS 0%

    webkul · bagistoJan 2, 2026