Перейти к содержимому
Noroxi

Записи Webkul

57 опубликованных записей вендора webkul.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
8
С записью об исправлении
45,6 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

57 записей
  • CVE-2024-0916
    40В плане

    Unauthenticated Remote Code Execution in UvDesk Community

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    webkul software · uvdesk community25 апр. 2024 г.

  • CVE-2023-51210
    39Наблюдать

    SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    webkul · bundle product23 янв. 2024 г.

  • CVE-2025-67325
    39Наблюдать

    Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achiev

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    webkul · qloapps8 янв. 2026 г.

  • CVE-2024-46367
    38Наблюдать

    A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    webkul · krayin crm27 сент. 2024 г.

  • CVE-2019-16403
    35Наблюдать

    In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can als

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webkul · bagisto18 сент. 2019 г.

  • CVE-2023-33570
    35Наблюдать

    Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webkul · bagisto28 июн. 2023 г.

  • CVE-2026-21448
    35Наблюдать

    Bagisto has Normal & Blind SSTI from low-privilege user when ordering product

    ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %

    webkul · bagisto2 янв. 2026 г.

  • CVE-2026-38529
    35Наблюдать

    A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webkul · krayin crm14 апр. 2026 г.

  • CVE-2026-21446
    35Наблюдать

    Bagisto Missing Authentication on Installer API Endpoints

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webkul · bagisto2 янв. 2026 г.

  • CVE-2019-14933
    35Наблюдать

    Bagisto 0.1.5 allows CSRF under /admin URIs.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webkul · bagisto11 авг. 2019 г.

  • CVE-2024-46366
    35Наблюдать

    A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side te

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    webkul · krayin crm27 сент. 2024 г.

  • CVE-2017-20262
    35Наблюдать

    Joomla! Component Ajax Quiz 1.8 SQL Injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    webkul · ajax quiz19 июн. 2026 г.

  • CVE-2023-36237
    35Наблюдать

    Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    webkul · bagisto26 февр. 2024 г.

  • CVE-2025-60880
    33Наблюдать

    An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a

    ВысокаяCVSS 8,3Proof of conceptEPSS 0 %

    webkul · bagisto10 окт. 2025 г.

  • CVE-2025-55741
    32Наблюдать

    unopim/unopim allows unauthorized product deletion via mass-delete endpoint

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    webkul · unopim22 авг. 2025 г.

  • CVE-2026-38532
    32Наблюдать

    A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenti

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    webkul · krayin crm14 апр. 2026 г.

  • CVE-2026-38530
    32Наблюдать

    A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authentic

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    webkul · krayin crm14 апр. 2026 г.

  • CVE-2023-36284
    31Наблюдать

    An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remo

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    webkul · qloapps23 июн. 2023 г.

  • CVE-2023-39147
    31Наблюдать

    An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

    ВысокаяCVSS 7,8Proof of conceptEPSS 1 %

    webkul · uvdesk1 авг. 2023 г.

  • CVE-2026-21450
    29Наблюдать

    Bagisto has SSTI in parameter that can lead to RCE

    ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %

    webkul · bagisto2 янв. 2026 г.

  • CVE-2026-21449
    29Наблюдать

    Bagisto has SSTI via first and last name from low-privilege user (not admin)

    ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %

    webkul · bagisto2 янв. 2026 г.

  • CVE-2025-55743
    29Наблюдать

    UnoPim vulnerable to remote code execution through Arbitrary File upload

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    webkul · unopim21 авг. 2025 г.

  • CVE-2024-40318
    28Наблюдать

    An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

    ВысокаяCVSS 7,2Proof of conceptEPSS 1 %

    webkul · qloapps25 июл. 2024 г.

  • CVE-2025-62417
    28Наблюдать

    bagisto - CSV Formula Injection in Create New Product

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    webkul · bagisto16 окт. 2025 г.

  • CVE-2026-21447
    28Наблюдать

    Bagisto has IDOR in Customer Order Reorder Functionality

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    webkul · bagisto2 янв. 2026 г.