VendorsWebkulqloappsany version
Vulnerabilities

Webkul QloApps any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-67325
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
Published 2026-01-08 · Analyzed
9.8EPSS 0.009
CVE-2023-36235
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
Published 2024-01-17 · Modified
6.5EPSS 0.007
CVE-2025-10759
Webkul QloApps CSRF Token authorization
Published 2025-09-21 · Analyzed
5.5EPSS 0.003