Vulnerabilities
55 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-20262 | Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mali Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cid parameter. Attackers can send GET requests to index.php with the option=com_ajaxquiz and view=ajaxquiz parameters to extract sensitive database information including table names and column structures. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2026-38529 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitraril A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2021-41074 | A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document. A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2025-67325 | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execut Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2026-21448 | Bagisto is an open source laravel eCommerce platform. Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The issue can lead to remote code execution. Version 2.3.10 contains a patch. NVD description · AI analysis pending | 8.9 group max | <1% | PoC |
| — | |
| CVE-2025-62417 | Bagisto is an open source laravel eCommerce platform. Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as a formula. This allows an attacker to supply a CSV field (e.g., product name) that contains a formula which may be evaluated by a victim’s spreadsheet application — potentially leading to data exfiltration and remote command execution (via older Excel exploits / OLE/cmd constructs or Excel macros). This vulnerability is fixed in 2.3.8. NVD description · AI analysis pending | 7.1 group max | <1% | PoC |
| — | |
| CVE-2025-60880 | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file con An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions. NVD description · AI analysis pending | 8.3 | <1% | PoC ×2 |
| — | |
| CVE-2025-56426 | An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2025-10759 | A vulnerability was detected in Webkul QloApps up to 1.7.0. A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We are already aware about this vulnerability and our Internal team are already working on this issue. (...) We'll implement the fix for this vulnerability in our next major release." NVD description · AI analysis pending | 5.5 | <1% | PoC ×2 |
| — | |
| CVE-2025-55741 +1 in the same advisory: …55745 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the Delete privilege for products are unable to delete individual products via the standard endpoint, as expected. However, these users can bypass intended access controls by issuing requests to the mass-delete endpoint, allowing them to delete products without proper authorization. This vulnerability allows unauthorized product deletion, leading to potential data loss and business disruption. The issue is fixed in version 0.3.1. No known workarounds exist. NVD description · AI analysis pending | 8.1 group max | <1% | PoC ×2 |
| — | |
| CVE-2025-55743 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creation feature performs only client side file type validation. A user can capture the request by uploading an image, capture the request through a Proxy like Burp suite. Make changes to the file extension and content. The vulnerability is fixed in 0.2.1. NVD description · AI analysis pending | 7.3 group max | <1% | PoC ×2 |
| — | |
| CVE-2025-6173 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this flaw but considers it a low-level issue due to admin privilege pre-requisites. Still, a fix is planned for a future release. NVD description · AI analysis pending | 2.0 | <1% | PoC ×2 |
| — | |
| CVE-2025-40675 | A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user. NVD description · AI analysis pending | 5.1 | <1% |
| — | ||
| CVE-2025-3568 | A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify for a CVE. NVD description · AI analysis pending | 5.1 | <1% | PoC ×2 |
| — | |
| CVE-2025-26058 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. NVD description · AI analysis pending | 4.2 | <1% | PoC |
| — | |
| CVE-2025-1155 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-1074 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure. They are aware about it and are working on resolving it. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-52305 | UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-50637 | UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-45932 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2024-46367 +1 in the same advisory: …46366 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicio A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system. NVD description · AI analysis pending | 9.6 group max | <1% |
| — | ||
| CVE-2024-40318 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2023-36238 | Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter. Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-27499 | Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-36237 | Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script. Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2023-51210 | SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProduct SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote attacker to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2023-36235 | An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2023-36236 | Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2023-37636 | A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted pa A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-39147 | An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file. An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file. NVD description · AI analysis pending | 7.8 | 1% | PoC ×2 |
| — | |
| CVE-2023-33570 | Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI). Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI). NVD description · AI analysis pending | 8.8 | 1% | PoC |
| — | |
| CVE-2023-36284 | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypas An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database. NVD description · AI analysis pending | 7.5 group max | 3% | PoC |
| — |