Записи Webkul
57 опубликованных записей вендора webkul.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 45,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-639 Authorization Bypass Through User-Controlled Key5
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-434 Unrestricted Upload of File with Dangerous Type5
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
57 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-0916Эксплойта нет | Unauthenticated Remote Code Execution in UvDesk Communitywebkul software · uvdesk community · CWE-434 | Критическая10,0 | — | 1,0 % | 25 апр. 2024 г. |
39Наблюдать | CVE-2023-51210Эксплойта нет | SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters webkul · bundle product · CWE-89 | Критическая9,8 | — | 1,1 % | 23 янв. 2024 г. |
39Наблюдать | CVE-2025-67325Proof of concept | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achievwebkul · qloapps · CWE-434 | Критическая9,8 | — | 0,9 % | 8 янв. 2026 г. |
38Наблюдать | CVE-2024-46367Эксплойта нет | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by webkul · krayin crm · CWE-79 | Критическая9,6 | — | 0,5 % | 27 сент. 2024 г. |
35Наблюдать | CVE-2019-16403Эксплойта нет | In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can alswebkul · bagisto · CWE-639 | Высокая8,8 | — | 1,4 % | 18 сент. 2019 г. |
35Наблюдать | CVE-2023-33570Эксплойта нет | Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).webkul · bagisto · CWE-94 | Высокая8,8 | — | 1,1 % | 28 июн. 2023 г. |
35Наблюдать | CVE-2026-21448Эксплойта нет | Bagisto has Normal & Blind SSTI from low-privilege user when ordering productwebkul · bagisto · CWE-1336 | Высокая8,9 | — | 0,9 % | 2 янв. 2026 г. |
35Наблюдать | CVE-2026-38529Эксплойта нет | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attwebkul · krayin crm · CWE-269 | Высокая8,8 | — | 0,8 % | 14 апр. 2026 г. |
35Наблюдать | CVE-2026-21446Эксплойта нет | Bagisto Missing Authentication on Installer API Endpointswebkul · bagisto · CWE-306 | Высокая8,8 | — | 0,6 % | 2 янв. 2026 г. |
35Наблюдать | CVE-2019-14933Эксплойта нет | Bagisto 0.1.5 allows CSRF under /admin URIs.webkul · bagisto · CWE-352 | Высокая8,8 | — | 0,6 % | 11 авг. 2019 г. |
35Наблюдать | CVE-2024-46366Эксплойта нет | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side tewebkul · krayin crm · CWE-1336 | Высокая8,8 | — | 0,5 % | 27 сент. 2024 г. |
35Наблюдать | CVE-2017-20262Эксплойта нет | Joomla! Component Ajax Quiz 1.8 SQL Injectionwebkul · ajax quiz · CWE-89 | Высокая8,8 | — | 0,5 % | 19 июн. 2026 г. |
35Наблюдать | CVE-2023-36237Эксплойта нет | Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.webkul · bagisto · CWE-352 | Высокая8,8 | — | 0,4 % | 26 февр. 2024 г. |
33Наблюдать | CVE-2025-60880Proof of concept | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a webkul · bagisto · CWE-79 | Высокая8,3 | — | 0,4 % | 10 окт. 2025 г. |
32Наблюдать | CVE-2025-55741Эксплойта нет | unopim/unopim allows unauthorized product deletion via mass-delete endpointwebkul · unopim · CWE-284 | Высокая8,1 | — | 0,4 % | 22 авг. 2025 г. |
32Наблюдать | CVE-2026-38532Эксплойта нет | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authentiwebkul · krayin crm · CWE-639 | Высокая8,1 | — | 0,4 % | 14 апр. 2026 г. |
32Наблюдать | CVE-2026-38530Эксплойта нет | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticwebkul · krayin crm · CWE-639 | Высокая8,1 | — | 0,4 % | 14 апр. 2026 г. |
31Наблюдать | CVE-2023-36284Proof of concept | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remowebkul · qloapps · CWE-89 | Высокая7,5 | — | 3,2 % | 23 июн. 2023 г. |
31Наблюдать | CVE-2023-39147Proof of concept | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.webkul · uvdesk · CWE-434 | Высокая7,8 | — | 1,2 % | 1 авг. 2023 г. |
29Наблюдать | CVE-2026-21450Эксплойта нет | Bagisto has SSTI in parameter that can lead to RCEwebkul · bagisto · CWE-1336 | Высокая7,3 | — | 1,4 % | 2 янв. 2026 г. |
29Наблюдать | CVE-2026-21449Эксплойта нет | Bagisto has SSTI via first and last name from low-privilege user (not admin)webkul · bagisto · CWE-1336 | Высокая7,4 | — | 0,5 % | 2 янв. 2026 г. |
29Наблюдать | CVE-2025-55743Эксплойта нет | UnoPim vulnerable to remote code execution through Arbitrary File uploadwebkul · unopim · CWE-434 | Высокая7,3 | — | 0,5 % | 21 авг. 2025 г. |
28Наблюдать | CVE-2024-40318Proof of concept | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.webkul · qloapps · CWE-434 | Высокая7,2 | — | 1,2 % | 25 июл. 2024 г. |
28Наблюдать | CVE-2025-62417Эксплойта нет | bagisto - CSV Formula Injection in Create New Productwebkul · bagisto · CWE-1236 | Высокая7,1 | — | 0,4 % | 16 окт. 2025 г. |
28Наблюдать | CVE-2026-21447Эксплойта нет | Bagisto has IDOR in Customer Order Reorder Functionalitywebkul · bagisto · CWE-284 | Высокая7,1 | — | 0,3 % | 2 янв. 2026 г. |
- CVE-2024-091640В плане
Unauthenticated Remote Code Execution in UvDesk Community
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %webkul software · uvdesk community25 апр. 2024 г.
- CVE-2023-5121039Наблюдать
SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %webkul · bundle product23 янв. 2024 г.
- CVE-2025-6732539Наблюдать
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achiev
КритическаяCVSS 9,8Proof of conceptEPSS 1 %webkul · qloapps8 янв. 2026 г.
- CVE-2024-4636738Наблюдать
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %webkul · krayin crm27 сент. 2024 г.
- CVE-2019-1640335Наблюдать
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can als
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webkul · bagisto18 сент. 2019 г.
- CVE-2023-3357035Наблюдать
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webkul · bagisto28 июн. 2023 г.
- CVE-2026-2144835Наблюдать
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
ВысокаяCVSS 8,9Эксплойта нетEPSS 1 %webkul · bagisto2 янв. 2026 г.
- CVE-2026-3852935Наблюдать
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webkul · krayin crm14 апр. 2026 г.
- CVE-2026-2144635Наблюдать
Bagisto Missing Authentication on Installer API Endpoints
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webkul · bagisto2 янв. 2026 г.
- CVE-2019-1493335Наблюдать
Bagisto 0.1.5 allows CSRF under /admin URIs.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webkul · bagisto11 авг. 2019 г.
- CVE-2024-4636635Наблюдать
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side te
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %webkul · krayin crm27 сент. 2024 г.
- CVE-2017-2026235Наблюдать
Joomla! Component Ajax Quiz 1.8 SQL Injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %webkul · ajax quiz19 июн. 2026 г.
- CVE-2023-3623735Наблюдать
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %webkul · bagisto26 февр. 2024 г.
- CVE-2025-6088033Наблюдать
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a
ВысокаяCVSS 8,3Proof of conceptEPSS 0 %webkul · bagisto10 окт. 2025 г.
- CVE-2025-5574132Наблюдать
unopim/unopim allows unauthorized product deletion via mass-delete endpoint
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %webkul · unopim22 авг. 2025 г.
- CVE-2026-3853232Наблюдать
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenti
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %webkul · krayin crm14 апр. 2026 г.
- CVE-2026-3853032Наблюдать
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authentic
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %webkul · krayin crm14 апр. 2026 г.
- CVE-2023-3628431Наблюдать
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remo
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %webkul · qloapps23 июн. 2023 г.
- CVE-2023-3914731Наблюдать
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %webkul · uvdesk1 авг. 2023 г.
- CVE-2026-2145029Наблюдать
Bagisto has SSTI in parameter that can lead to RCE
ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %webkul · bagisto2 янв. 2026 г.
- CVE-2026-2144929Наблюдать
Bagisto has SSTI via first and last name from low-privilege user (not admin)
ВысокаяCVSS 7,4Эксплойта нетEPSS 1 %webkul · bagisto2 янв. 2026 г.
- CVE-2025-5574329Наблюдать
UnoPim vulnerable to remote code execution through Arbitrary File upload
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %webkul · unopim21 авг. 2025 г.
- CVE-2024-4031828Наблюдать
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %webkul · qloapps25 июл. 2024 г.
- CVE-2025-6241728Наблюдать
bagisto - CSV Formula Injection in Create New Product
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %webkul · bagisto16 окт. 2025 г.
- CVE-2026-2144728Наблюдать
Bagisto has IDOR in Customer Order Reorder Functionality
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %webkul · bagisto2 янв. 2026 г.