Known Vulnerabilities for Qloapps by Webkul
Listed below are 7 of the newest known vulnerabilities associated with "Qloapps" by "Webkul".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-105836 json | QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms t... | Not Provided | 2026-10-06 | 2026-10-06 |
| CVE-2026-103590 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of... | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-103589 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails ... | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-103588 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Tran... | Not Provided | 2026-09-30 | 2026-10-05 |
| CVE-2026-103587 json | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Boo... | Not Provided | 2026-09-30 | 2026-10-01 |
| CVE-2026-93988 json | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authen... | Not Provided | 2026-09-19 | 2026-09-21 |
| CVE-2026-92234 json | QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservat... | Not Provided | 2026-09-15 | 2026-09-16 |
| CVE-2026-89268 json | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them ... | Not Provided | 2026-09-12 | 2026-09-14 |
| CVE-2026-75498 json | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administra... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-75497 json | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administra... | Not Provided | 2026-08-25 | 2026-08-25 |