Vulnerabilities in Webkul
23 resultsVexday analysis
Webkul registra 11 vulnerabilidades no histórico, com 3 divulgações nos últimos 90 dias, indicando atividade moderada de descobertas. Nenhuma vulnerabilidade está sob ataque ativo (KEV), reduzindo o risco imediato, embora 2 sejam críticas; a fraqueza dominante é XSS (CWE-79), típica de aplicações web e potencialmente explorada em massa. O fornecedor requer monitoramento contínuo, mas não apresenta urgência crítica no momento.
CVE-2024-11281CRITICALWooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email ChangeEPSS 1.5%CVE-2026-9506HIGHPath Traversal Vulnerability in BagistoEPSS 1.2%CVE-2023-2925LOWWebkul krayin crm Edit Person Page 2 cross site scriptingEPSS 0.6%CVE-2025-29009CRITICALWordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload VulnerabilityEPSS 0.5%CVE-2025-1155MEDIUMWebkul QloApps Your Location Search stores cross site scriptingEPSS 0.5%CVE-2025-6173MEDIUMWebkul QloApps ajax_products_list.php sql injectionEPSS 0.5%CVE-2017-20262HIGHJoomla! Component Ajax Quiz 1.8 SQL InjectionEPSS 0.4%CVE-2026-19997MEDIUMWebkul Bagisto Backend Sales RMA Endpoint requests authorizationEPSS 0.4%CVE-2025-3568MEDIUMWebkul Krayin CRM SVG File edit cross site scriptingEPSS 0.4%CVE-2026-19837MEDIUMWebkul Bagisto Customer Search search information disclosureEPSS 0.4%CVE-2026-19996MEDIUMWebkul Bagisto Backend Customer Behavior Data Endpoint customers privileges managementEPSS 0.3%CVE-2025-1074MEDIUMWebkul QloApps URL mylogout cross-site request forgeryEPSS 0.3%CVE-2025-10759MEDIUMWebkul QloApps CSRF Token authorizationEPSS 0.3%CVE-2026-19834MEDIUMWebkul Bagisto Admin Customer Impersonation Feature login-as-customer authorizationEPSS 0.3%CVE-2026-19836MEDIUMWebkul Bagisto Backend Customer Detail Feature view authorizationEPSS 0.3%CVE-2026-19838MEDIUMWebkul Bagisto Backend Reporting Endpoint sales authorizationEPSS 0.3%CVE-2026-19994MEDIUMWebkul Bagisto Configuration Management execute authorizationEPSS 0.3%CVE-2026-19993MEDIUMWebkul Bagisto RMA State Validation update-status behavioral workflowEPSS 0.3%CVE-2026-19835MEDIUMWebkul Bagisto Customer Item Deletion Endpoint access controlEPSS 0.3%CVE-2026-60120MEDIUMBagisto < 2.4.4 Stored XSS via CSTI in create.blade.phpEPSS 0.2%