Known Vulnerabilities for Qloapps by Webkul
Listed below are 7 of the newest known vulnerabilities associated with "Qloapps" by "Webkul".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-92234 json | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservat... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-89268 json | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them ... | Not Provided | 2026-09-12 | 2026-09-14 |
| CVE-2026-75498 json | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administra... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-75497 json | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administra... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-75496 json | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publi... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-25861 json | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers t... | Not Provided | 2026-06-02 | 2026-07-14 |
| CVE-2026-25558 json | QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticate... | Not Provided | 2026-06-08 | 2026-07-14 |
| CVE-2025-6173 json | Not Provided | 2025-06-17 | 2026-04-29 | |
| CVE-2023-36289 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 6.1 - MEDIUM | 2023-06-23 | 2023-06-29 |
| CVE-2023-36288 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 5.4 - MEDIUM | 2023-06-23 | 2023-06-29 |