Webkul records
57 published records for vendor webkul.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 45.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-639 Authorization Bypass Through User-Controlled Key5
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
57 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2024-0916No exploit | Unauthenticated Remote Code Execution in UvDesk Communitywebkul software · uvdesk community · CWE-434 | Critical10.0 | — | 1.0% | Apr 25, 2024 |
39Monitor | CVE-2023-51210No exploit | SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters webkul · bundle product · CWE-89 | Critical9.8 | — | 1.1% | Jan 23, 2024 |
39Monitor | CVE-2025-67325Proof of concept | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achievwebkul · qloapps · CWE-434 | Critical9.8 | — | 0.9% | Jan 8, 2026 |
38Monitor | CVE-2024-46367No exploit | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by webkul · krayin crm · CWE-79 | Critical9.6 | — | 0.5% | Sep 27, 2024 |
35Monitor | CVE-2019-16403No exploit | In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can alswebkul · bagisto · CWE-639 | High8.8 | — | 1.4% | Sep 18, 2019 |
35Monitor | CVE-2023-33570No exploit | Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).webkul · bagisto · CWE-94 | High8.8 | — | 1.1% | Jun 28, 2023 |
35Monitor | CVE-2026-21448No exploit | Bagisto has Normal & Blind SSTI from low-privilege user when ordering productwebkul · bagisto · CWE-1336 | High8.9 | — | 0.9% | Jan 2, 2026 |
35Monitor | CVE-2026-38529No exploit | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attwebkul · krayin crm · CWE-269 | High8.8 | — | 0.8% | Apr 14, 2026 |
35Monitor | CVE-2026-21446No exploit | Bagisto Missing Authentication on Installer API Endpointswebkul · bagisto · CWE-306 | High8.8 | — | 0.6% | Jan 2, 2026 |
35Monitor | CVE-2019-14933No exploit | Bagisto 0.1.5 allows CSRF under /admin URIs.webkul · bagisto · CWE-352 | High8.8 | — | 0.6% | Aug 11, 2019 |
35Monitor | CVE-2024-46366No exploit | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side tewebkul · krayin crm · CWE-1336 | High8.8 | — | 0.5% | Sep 27, 2024 |
35Monitor | CVE-2017-20262No exploit | Joomla! Component Ajax Quiz 1.8 SQL Injectionwebkul · ajax quiz · CWE-89 | High8.8 | — | 0.5% | Jun 19, 2026 |
35Monitor | CVE-2023-36237No exploit | Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.webkul · bagisto · CWE-352 | High8.8 | — | 0.4% | Feb 26, 2024 |
33Monitor | CVE-2025-60880Proof of concept | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a webkul · bagisto · CWE-79 | High8.3 | — | 0.4% | Oct 10, 2025 |
32Monitor | CVE-2025-55741No exploit | unopim/unopim allows unauthorized product deletion via mass-delete endpointwebkul · unopim · CWE-284 | High8.1 | — | 0.4% | Aug 22, 2025 |
32Monitor | CVE-2026-38532No exploit | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authentiwebkul · krayin crm · CWE-639 | High8.1 | — | 0.4% | Apr 14, 2026 |
32Monitor | CVE-2026-38530No exploit | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticwebkul · krayin crm · CWE-639 | High8.1 | — | 0.4% | Apr 14, 2026 |
31Monitor | CVE-2023-36284Proof of concept | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remowebkul · qloapps · CWE-89 | High7.5 | — | 3.2% | Jun 23, 2023 |
31Monitor | CVE-2023-39147Proof of concept | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.webkul · uvdesk · CWE-434 | High7.8 | — | 1.2% | Aug 1, 2023 |
29Monitor | CVE-2026-21450No exploit | Bagisto has SSTI in parameter that can lead to RCEwebkul · bagisto · CWE-1336 | High7.3 | — | 1.4% | Jan 2, 2026 |
29Monitor | CVE-2026-21449No exploit | Bagisto has SSTI via first and last name from low-privilege user (not admin)webkul · bagisto · CWE-1336 | High7.4 | — | 0.5% | Jan 2, 2026 |
29Monitor | CVE-2025-55743No exploit | UnoPim vulnerable to remote code execution through Arbitrary File uploadwebkul · unopim · CWE-434 | High7.3 | — | 0.5% | Aug 21, 2025 |
28Monitor | CVE-2024-40318Proof of concept | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.webkul · qloapps · CWE-434 | High7.2 | — | 1.2% | Jul 25, 2024 |
28Monitor | CVE-2025-62417No exploit | bagisto - CSV Formula Injection in Create New Productwebkul · bagisto · CWE-1236 | High7.1 | — | 0.4% | Oct 16, 2025 |
28Monitor | CVE-2026-21447No exploit | Bagisto has IDOR in Customer Order Reorder Functionalitywebkul · bagisto · CWE-284 | High7.1 | — | 0.3% | Jan 2, 2026 |
- CVE-2024-091640Plan
Unauthenticated Remote Code Execution in UvDesk Community
CriticalCVSS 10.0No exploitEPSS 1%webkul software · uvdesk communityApr 25, 2024
- CVE-2023-5121039Monitor
SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters
CriticalCVSS 9.8No exploitEPSS 1%webkul · bundle productJan 23, 2024
- CVE-2025-6732539Monitor
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achiev
CriticalCVSS 9.8Proof of conceptEPSS 1%webkul · qloappsJan 8, 2026
- CVE-2024-4636738Monitor
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by
CriticalCVSS 9.6No exploitEPSS 1%webkul · krayin crmSep 27, 2024
- CVE-2019-1640335Monitor
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can als
HighCVSS 8.8No exploitEPSS 1%webkul · bagistoSep 18, 2019
- CVE-2023-3357035Monitor
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
HighCVSS 8.8No exploitEPSS 1%webkul · bagistoJun 28, 2023
- CVE-2026-2144835Monitor
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
HighCVSS 8.9No exploitEPSS 1%webkul · bagistoJan 2, 2026
- CVE-2026-3852935Monitor
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att
HighCVSS 8.8No exploitEPSS 1%webkul · krayin crmApr 14, 2026
- CVE-2026-2144635Monitor
Bagisto Missing Authentication on Installer API Endpoints
HighCVSS 8.8No exploitEPSS 1%webkul · bagistoJan 2, 2026
- CVE-2019-1493335Monitor
Bagisto 0.1.5 allows CSRF under /admin URIs.
HighCVSS 8.8No exploitEPSS 1%webkul · bagistoAug 11, 2019
- CVE-2024-4636635Monitor
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side te
HighCVSS 8.8No exploitEPSS 1%webkul · krayin crmSep 27, 2024
- CVE-2017-2026235Monitor
Joomla! Component Ajax Quiz 1.8 SQL Injection
HighCVSS 8.8No exploitEPSS 0%webkul · ajax quizJun 19, 2026
- CVE-2023-3623735Monitor
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
HighCVSS 8.8No exploitEPSS 0%webkul · bagistoFeb 26, 2024
- CVE-2025-6088033Monitor
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a
HighCVSS 8.3Proof of conceptEPSS 0%webkul · bagistoOct 10, 2025
- CVE-2025-5574132Monitor
unopim/unopim allows unauthorized product deletion via mass-delete endpoint
HighCVSS 8.1No exploitEPSS 0%webkul · unopimAug 22, 2025
- CVE-2026-3853232Monitor
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenti
HighCVSS 8.1No exploitEPSS 0%webkul · krayin crmApr 14, 2026
- CVE-2026-3853032Monitor
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authentic
HighCVSS 8.1No exploitEPSS 0%webkul · krayin crmApr 14, 2026
- CVE-2023-3628431Monitor
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remo
HighCVSS 7.5Proof of conceptEPSS 3%webkul · qloappsJun 23, 2023
- CVE-2023-3914731Monitor
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
HighCVSS 7.8Proof of conceptEPSS 1%webkul · uvdeskAug 1, 2023
- CVE-2026-2145029Monitor
Bagisto has SSTI in parameter that can lead to RCE
HighCVSS 7.3No exploitEPSS 1%webkul · bagistoJan 2, 2026
- CVE-2026-2144929Monitor
Bagisto has SSTI via first and last name from low-privilege user (not admin)
HighCVSS 7.4No exploitEPSS 1%webkul · bagistoJan 2, 2026
- CVE-2025-5574329Monitor
UnoPim vulnerable to remote code execution through Arbitrary File upload
HighCVSS 7.3No exploitEPSS 0%webkul · unopimAug 21, 2025
- CVE-2024-4031828Monitor
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
HighCVSS 7.2Proof of conceptEPSS 1%webkul · qloappsJul 25, 2024
- CVE-2025-6241728Monitor
bagisto - CSV Formula Injection in Create New Product
HighCVSS 7.1No exploitEPSS 0%webkul · bagistoOct 16, 2025
- CVE-2026-2144728Monitor
Bagisto has IDOR in Customer Order Reorder Functionality
HighCVSS 7.1No exploitEPSS 0%webkul · bagistoJan 2, 2026