Known Vulnerabilities for Qloapps by Webkul
Listed below are 7 of the newest known vulnerabilities associated with "Qloapps" by "Webkul".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75498 json | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administra... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-75497 json | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administra... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-75496 json | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publi... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-25861 json | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers t... | Not Provided | 2026-06-02 | 2026-07-14 |
| CVE-2026-25558 json | QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticate... | Not Provided | 2026-06-08 | 2026-07-14 |
| CVE-2025-6173 json | Not Provided | 2025-06-17 | 2026-04-29 | |
| CVE-2023-36289 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 6.1 - MEDIUM | 2023-06-23 | 2023-06-29 |
| CVE-2023-36288 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 5.4 - MEDIUM | 2023-06-23 | 2023-06-29 |
| CVE-2023-36287 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 6.1 - MEDIUM | 2023-06-23 | 2023-06-29 |
| CVE-2023-36284 json | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_produc... | 7.5 - HIGH | 2023-06-23 | 2023-06-30 |