Vulnerabilities (CVE)

Filtered by vendor Webkul Subscribe
Filtered by product Qloapps
Total 9 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-6173 1 Webkul 1 Qloapps 2025-06-26 5.8 MEDIUM 4.7 MEDIUM
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this flaw but considers it a low-level issue due to admin privilege pre-requisites. Still, a fix is planned for a future release.
CVE-2025-1155 1 Webkul 1 Qloapps 2025-06-20 5.0 MEDIUM 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long term.
CVE-2023-36235 1 Webkul 1 Qloapps 2025-06-10 N/A 6.5 MEDIUM
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
CVE-2023-30256 1 Webkul 1 Qloapps 2025-01-27 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file.
CVE-2024-40318 1 Webkul 1 Qloapps 2024-11-21 N/A 7.2 HIGH
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2023-36289 1 Webkul 1 Qloapps 2024-11-21 N/A 6.1 MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter.
CVE-2023-36288 1 Webkul 1 Qloapps 2024-11-21 N/A 5.4 MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter.
CVE-2023-36287 1 Webkul 1 Qloapps 2024-11-21 N/A 6.1 MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter.
CVE-2023-36284 1 Webkul 1 Qloapps 2024-11-21 N/A 7.5 HIGH
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.