İçeriğe atla
Noroxi

Webkul kayıtları

webkul üreticisine ait 57 yayımlanmış kayıt.

Tüm kayıtlar

57 kayıt
  • CVE-2024-0916
    40Planlayın

    Unauthenticated Remote Code Execution in UvDesk Community

    KritikCVSS 10,0İstismar yokEPSS %1

    webkul software · uvdesk community25 Nis 2024

  • CVE-2023-51210
    39İzleyin

    SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters

    KritikCVSS 9,8İstismar yokEPSS %1

    webkul · bundle product23 Oca 2024

  • CVE-2025-67325
    39İzleyin

    Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achiev

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    webkul · qloapps8 Oca 2026

  • CVE-2024-46367
    38İzleyin

    A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by

    KritikCVSS 9,6İstismar yokEPSS %1

    webkul · krayin crm27 Eyl 2024

  • CVE-2019-16403
    35İzleyin

    In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can als

    YüksekCVSS 8,8İstismar yokEPSS %1

    webkul · bagisto18 Eyl 2019

  • CVE-2023-33570
    35İzleyin

    Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

    YüksekCVSS 8,8İstismar yokEPSS %1

    webkul · bagisto28 Haz 2023

  • CVE-2026-21448
    35İzleyin

    Bagisto has Normal & Blind SSTI from low-privilege user when ordering product

    YüksekCVSS 8,9İstismar yokEPSS %1

    webkul · bagisto2 Oca 2026

  • CVE-2026-38529
    35İzleyin

    A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att

    YüksekCVSS 8,8İstismar yokEPSS %1

    webkul · krayin crm14 Nis 2026

  • CVE-2026-21446
    35İzleyin

    Bagisto Missing Authentication on Installer API Endpoints

    YüksekCVSS 8,8İstismar yokEPSS %1

    webkul · bagisto2 Oca 2026

  • CVE-2019-14933
    35İzleyin

    Bagisto 0.1.5 allows CSRF under /admin URIs.

    YüksekCVSS 8,8İstismar yokEPSS %1

    webkul · bagisto11 Ağu 2019

  • CVE-2024-46366
    35İzleyin

    A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side te

    YüksekCVSS 8,8İstismar yokEPSS %1

    webkul · krayin crm27 Eyl 2024

  • CVE-2017-20262
    35İzleyin

    Joomla! Component Ajax Quiz 1.8 SQL Injection

    YüksekCVSS 8,8İstismar yokEPSS %0

    webkul · ajax quiz19 Haz 2026

  • CVE-2023-36237
    35İzleyin

    Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

    YüksekCVSS 8,8İstismar yokEPSS %0

    webkul · bagisto26 Şub 2024

  • CVE-2025-60880
    33İzleyin

    An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a

    YüksekCVSS 8,3Kavram kanıtıEPSS %0

    webkul · bagisto10 Eki 2025

  • CVE-2025-55741
    32İzleyin

    unopim/unopim allows unauthorized product deletion via mass-delete endpoint

    YüksekCVSS 8,1İstismar yokEPSS %0

    webkul · unopim22 Ağu 2025

  • CVE-2026-38532
    32İzleyin

    A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenti

    YüksekCVSS 8,1İstismar yokEPSS %0

    webkul · krayin crm14 Nis 2026

  • CVE-2026-38530
    32İzleyin

    A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authentic

    YüksekCVSS 8,1İstismar yokEPSS %0

    webkul · krayin crm14 Nis 2026

  • CVE-2023-36284
    31İzleyin

    An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remo

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    webkul · qloapps23 Haz 2023

  • CVE-2023-39147
    31İzleyin

    An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.

    YüksekCVSS 7,8Kavram kanıtıEPSS %1

    webkul · uvdesk1 Ağu 2023

  • CVE-2026-21450
    29İzleyin

    Bagisto has SSTI in parameter that can lead to RCE

    YüksekCVSS 7,3İstismar yokEPSS %1

    webkul · bagisto2 Oca 2026

  • CVE-2026-21449
    29İzleyin

    Bagisto has SSTI via first and last name from low-privilege user (not admin)

    YüksekCVSS 7,4İstismar yokEPSS %1

    webkul · bagisto2 Oca 2026

  • CVE-2025-55743
    29İzleyin

    UnoPim vulnerable to remote code execution through Arbitrary File upload

    YüksekCVSS 7,3İstismar yokEPSS %0

    webkul · unopim21 Ağu 2025

  • CVE-2024-40318
    28İzleyin

    An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

    YüksekCVSS 7,2Kavram kanıtıEPSS %1

    webkul · qloapps25 Tem 2024

  • CVE-2025-62417
    28İzleyin

    bagisto - CSV Formula Injection in Create New Product

    YüksekCVSS 7,1İstismar yokEPSS %0

    webkul · bagisto16 Eki 2025

  • CVE-2026-21447
    28İzleyin

    Bagisto has IDOR in Customer Order Reorder Functionality

    YüksekCVSS 7,1İstismar yokEPSS %0

    webkul · bagisto2 Oca 2026