Skip to main content

Vendor/product archive

webkul / unopim CVEs

Beta · best-effort

7 CVEs tagged to webkul / unopim0 Critical, 3 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2025-55745

Published Aug 22, 2025

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV injection, also known as formul…

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-55741

Published Aug 22, 2025

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55744

Published Aug 21, 2025

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some of the endpoints of the application is vulnerable to Cross…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55743

Published Aug 21, 2025

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only clie…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-55742

Published Aug 21, 2025

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPim contains a stored cross-site scripting vulnerability via…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52305

Published Nov 13, 2024

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50637

Published Nov 6, 2024

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to stea…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1