VendorsWebkulqloapps1.6.1
Vulnerabilities

Webkul QloApps 1.6.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2025-6173
Webkul QloApps ajax_products_list.php sql injection
Published 2025-06-17 · Analyzed
7.2EPSS 0.006
CVE-2025-1155
Webkul QloApps Your Location Search stores cross site scripting
Published 2025-02-10 · Analyzed
6.1EPSS 0.005
CVE-2025-1074
Webkul QloApps URL mylogout cross-site request forgery
Published 2025-02-06 · Analyzed
5.3EPSS 0.003
CVE-2025-26058
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL.
Published 2025-02-18 · Analyzed
4.2EPSS 0.002