Home / CVEs we hold for Webkul CVEs we hold for Webkul Records whose assigning authority named Webkul as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-9506 Path Traversal Vulnerability in Bagisto Webkul Bagisto CVE-2026-93454 Aureus ERP through 1.6.0 Stored XSS via Payment Term Note Webkul Aureus ERP CVE-2026-92234 QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors Webkul QloApps CVE-2026-89268 QloApps through 1.7.0 Reflected XSS via List Filter Parameters Webkul QloApps CVE-2026-75496 Webkul QloApps improper file upload validation Webkul QloApps CVE-2026-75082 Webkul Bagisto Customer-Registration Notification Email register cross site scripting Webkul Bagisto CVE-2026-60120 Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php Webkul Bagisto CVE-2026-19997 Webkul Bagisto Backend Sales RMA Endpoint requests authorization Webkul Bagisto CVE-2026-19996 Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management Webkul Bagisto CVE-2026-19995 Webkul Bagisto RMA Message send-message cross site scripting Webkul Bagisto CVE-2026-19994 Webkul Bagisto Configuration Management execute authorization Webkul Bagisto CVE-2026-19993 Webkul Bagisto RMA State Validation update-status behavioral workflow Webkul Bagisto CVE-2026-19838 Webkul Bagisto Backend Reporting Endpoint sales authorization Webkul Bagisto CVE-2026-19837 Webkul Bagisto Customer Search search information disclosure Webkul Bagisto CVE-2026-19836 Webkul Bagisto Backend Customer Detail Feature view authorization Webkul Bagisto CVE-2026-19835 Webkul Bagisto Customer Item Deletion Endpoint access control Webkul Bagisto CVE-2026-19834 Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization Webkul Bagisto CVE-2025-6173 Webkul QloApps ajax_products_list.php sql injection Webkul QloApps CVE-2025-3568 Webkul Krayin CRM SVG File edit cross site scripting Webkul Krayin CRM CVE-2025-29009 WordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload Vulnerability Webkul Medical Prescription Attachment Plugin for… CVE-2025-1155 Webkul QloApps Your Location Search stores cross site scripting Webkul QloApps CVE-2025-1074 Webkul QloApps URL mylogout cross-site request forgery Webkul QloApps CVE-2024-11281 WooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email… Webkul WooCommerce Point of Sale CVE-2024-0916 Unauthenticated Remote Code Execution in UvDesk Community Webkul Software UvDesk Community CVE-2023-2925 Webkul krayin crm Edit Person Page 2 cross site scripting Webkul krayin crm CVE-2017-20262 Joomla! Component Ajax Quiz 1.8 SQL Injection Webkul Ajax Quiz 30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.