VendorsWebkulqloappsall versions
Vulnerabilities

Webkul QloApps

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2025-67325
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
Published 2026-01-08 · Analyzed
9.8EPSS 0.009
CVE-2023-36284
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
Published 2023-06-23 · Modified
7.5EPSS 0.032
CVE-2024-40318
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
Published 2024-07-25 · Modified
7.2EPSS 0.012
CVE-2025-6173
Webkul QloApps ajax_products_list.php sql injection
Published 2025-06-17 · Analyzed
7.2EPSS 0.006
CVE-2023-36235
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
Published 2024-01-17 · Modified
6.5EPSS 0.007
CVE-2023-30256
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
Published 2023-05-11 · Modified
6.11 PoCEPSS 0.091
CVE-2023-36287
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
Published 2023-06-23 · Modified
6.1EPSS 0.012
CVE-2023-36289
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
Published 2023-06-23 · Modified
6.1EPSS 0.012
CVE-2025-1155
Webkul QloApps Your Location Search stores cross site scripting
Published 2025-02-10 · Analyzed
6.1EPSS 0.005
CVE-2025-10759
Webkul QloApps CSRF Token authorization
Published 2025-09-21 · Analyzed
5.5EPSS 0.003
CVE-2023-36288
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
Published 2023-06-23 · Modified
5.4EPSS 0.004
CVE-2021-41074
A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
Published 2026-01-12 · Analyzed
5.4EPSS 0.001
CVE-2025-1074
Webkul QloApps URL mylogout cross-site request forgery
Published 2025-02-06 · Analyzed
5.3EPSS 0.003
CVE-2025-26058
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
Published 2025-02-18 · Analyzed
4.2EPSS 0.002