Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
webkul vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2023-36287
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an malicious user to obtain a user's session cookie and then impersonate that user via POST controller parameter.
Webkul Qloapps 1.6.0
5.4
CVSSv3
CVE-2023-36288
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an malicious user to obtain a user's session cookie and then impersonate that user via GET configure parameter.
Webkul Qloapps 1.6.0
6.1
CVSSv3
CVE-2023-36289
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an malicious user to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
Webkul Qloapps 1.6.0
NA
CVE-2010-1659
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote malicious users to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.
Webkul Com Ultimateportfolio 1.0
1 EDB exploit
9.8
CVSSv3
CVE-2023-51210
SQL injection vulnerability in Webkul Bundle Product 6.0.1 allows a remote malicious user to execute arbitrary code via the id_product parameters in the UpdateProductQuantity function.
Webkul Bundle Product 6.0.1
5.4
CVSSv3
CVE-2023-2925
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting...
Webkul Krayin Crm 1.2.4
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-38002
CVE-2006-4304
CVE-2024-4336
CVE-2024-33437
CVE-2024-4340
CVE-2024-27956
privilege
insecure direct object reference
XSS
item search icon">CVE-2024-25938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2