Skip to main content

Vendor/product archive

webkul / qloapps CVEs

Beta · best-effort

14 CVEs tagged to webkul / qloapps1 Critical, 2 High, 10 Medium, 1 Low, 0 Unrated.

CVE-2021-41074

Published Jan 12, 2026

A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67325

Published Jan 8, 2026

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-10759

Published Sep 21, 2025

A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token res…

CVSS 5.5 · Medium
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-6173

Published Jun 17, 2025

A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The…

CVSS 2.0 · Low
evidence mentions
5
Buzz score
28.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-26058

Published Feb 18, 2025

Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authe…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
16.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1155

Published Feb 10, 2025

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. Th…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-1074

Published Feb 6, 2025

A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. Th…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
27.1
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-40318

Published Jul 25, 2024

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36235

Published Jan 17, 2024

An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36287

Published Jun 23, 2023

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via P…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36284

Published Jun 23, 2023

An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36289

Published Jun 23, 2023

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via P…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36288

Published Jun 23, 2023

An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via G…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-30256

Published May 11, 2023

Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthCon…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1