VendorsWebkulunopimall versions
Vulnerabilities

Webkul Software UnoPim

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2025-55745
UnoPim Quick Export feature is vulnerable to CSV injection
Published 2025-08-22 · Analyzed
8.8EPSS 0.006
CVE-2025-55743
UnoPim vulnerable to remote code execution through Arbitrary File upload
Published 2025-08-21 · Analyzed
8.8EPSS 0.005
CVE-2025-55741
unopim/unopim allows unauthorized product deletion via mass-delete endpoint
Published 2025-08-22 · Analyzed
8.1EPSS 0.004
CVE-2025-55742
UnoPim Stored XSS via SVG MIME/Sanitizer Bypass
Published 2025-08-21 · Analyzed
8.0EPSS 0.004
CVE-2025-55744
UnoPim vulnerable to CSRF on Product edit feature and creation of other types
Published 2025-08-21 · Analyzed
6.9EPSS 0.002
CVE-2024-52305
UnoPim Stored XSS : Cookie hijacking through Create User function
Published 2024-11-13 · Analyzed
6.5EPSS 0.002
CVE-2024-50637
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
Published 2024-11-06 · Analyzed
5.4EPSS 0.004