Known Vulnerabilities for products from Webkul
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Webkul".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-75498 json | Not Provided | 2026-08-25 | 2026-08-25 | |
| CVE-2026-75497 json | Not Provided | 2026-08-25 | 2026-08-25 | |
| CVE-2026-75496 json | Not Provided | 2026-08-25 | 2026-08-25 | |
| CVE-2026-75082 json | Not Provided | 2026-08-18 | 2026-08-18 | |
| CVE-2026-75081 json | Not Provided | 2026-08-18 | 2026-08-18 | |
| CVE-2026-38532 json | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x ... | Not Provided | 2026-04-14 | 2026-04-23 |
| CVE-2026-38530 json | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x a... | Not Provided | 2026-04-14 | 2026-04-23 |
| CVE-2026-38529 json | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows au... | Not Provided | 2026-04-14 | 2026-04-23 |
| CVE-2026-19997 json | Not Provided | 2026-08-17 | 2026-08-17 | |
| CVE-2026-19996 json | Not Provided | 2026-08-17 | 2026-08-18 | |
| CVE-2026-19995 json | Not Provided | 2026-08-17 | 2026-08-17 | |
| CVE-2026-19994 json | Not Provided | 2026-08-17 | 2026-08-19 | |
| CVE-2026-19993 json | Not Provided | 2026-08-17 | 2026-08-18 | |
| CVE-2025-6173 json | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functi... | Not Provided | 2025-06-17 | 2026-04-29 |
| CVE-2024-45932 json | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organization... | Not Provided | 2024-10-07 | 2026-07-05 |
| CVE-2023-51210 json | 9.8 - CRITICAL | 2024-01-23 | 2024-01-29 | |
| CVE-2023-39147 json | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted ima... | 7.8 - HIGH | 2023-08-01 | 2023-08-04 |
| CVE-2023-37636 json | A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary w... | 5.4 - MEDIUM | 2023-10-23 | 2023-10-30 |
| CVE-2023-36289 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 6.1 - MEDIUM | 2023-06-23 | 2023-06-29 |
| CVE-2023-36288 json | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user... | 5.4 - MEDIUM | 2023-06-23 | 2023-06-29 |
Known software with vulnerabilities from Webkul
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Webkul | Bagisto | 0.1.0 |