vciy

CVEs we hold for Webkul

Records whose assigning authority named Webkul as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9506Path Traversal Vulnerability in BagistoWebkul Bagisto
CVE-2026-93454Aureus ERP through 1.6.0 Stored XSS via Payment Term NoteWebkul Aureus ERP
CVE-2026-92234QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation ErrorsWebkul QloApps
CVE-2026-89268QloApps through 1.7.0 Reflected XSS via List Filter ParametersWebkul QloApps
CVE-2026-75498Webkul QloApps SQL injectionWebkul QloApps
CVE-2026-75497Webkul QloApps SQL injectionWebkul QloApps
CVE-2026-75496Webkul QloApps improper file upload validationWebkul QloApps
CVE-2026-75082Webkul Bagisto Customer-Registration Notification Email register cross site scriptingWebkul Bagisto
CVE-2026-75081Webkul Bagisto store behavioral workflowWebkul Bagisto
CVE-2026-60120Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.phpWebkul Bagisto
CVE-2026-19997Webkul Bagisto Backend Sales RMA Endpoint requests authorizationWebkul Bagisto
CVE-2026-19996Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges managementWebkul Bagisto
CVE-2026-19995Webkul Bagisto RMA Message send-message cross site scriptingWebkul Bagisto
CVE-2026-19994Webkul Bagisto Configuration Management execute authorizationWebkul Bagisto
CVE-2026-19993Webkul Bagisto RMA State Validation update-status behavioral workflowWebkul Bagisto
CVE-2026-19838Webkul Bagisto Backend Reporting Endpoint sales authorizationWebkul Bagisto
CVE-2026-19837Webkul Bagisto Customer Search search information disclosureWebkul Bagisto
CVE-2026-19836Webkul Bagisto Backend Customer Detail Feature view authorizationWebkul Bagisto
CVE-2026-19835Webkul Bagisto Customer Item Deletion Endpoint access controlWebkul Bagisto
CVE-2026-19834Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorizationWebkul Bagisto
CVE-2025-6173Webkul QloApps ajax_products_list.php sql injectionWebkul QloApps
CVE-2025-3568Webkul Krayin CRM SVG File edit cross site scriptingWebkul Krayin CRM
CVE-2025-29009WordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload VulnerabilityWebkul Medical Prescription Attachment Plugin for…
CVE-2025-1155Webkul QloApps Your Location Search stores cross site scriptingWebkul QloApps
CVE-2025-10759Webkul QloApps CSRF Token authorizationWebkul QloApps
CVE-2025-1074Webkul QloApps URL mylogout cross-site request forgeryWebkul QloApps
CVE-2024-11281WooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email…Webkul WooCommerce Point of Sale
CVE-2024-0916Unauthenticated Remote Code Execution in UvDesk CommunityWebkul Software UvDesk Community
CVE-2023-2925Webkul krayin crm Edit Person Page 2 cross site scriptingWebkul krayin crm
CVE-2017-20262Joomla! Component Ajax Quiz 1.8 SQL InjectionWebkul Ajax Quiz

30 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.