webkul
Security Risk Profile
58
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 58 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 30, 2010 to present
58
Total CVEs
30
Critical+High
2
Exploited
16
Unpatched
Threat Assessment
Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
16
Critical/High
Risk Level
58/100
medium
⚠️ 2 Active Exploits
Severity Distribution
Critical
9High
21Medium
27Low
1Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
10Age Distribution
Common Weaknesses (CWE)
1
XSS
23
2
CSRF
9
3
Malicious File Upload
6
4
Code Injection
4
5
Command Injection
3
Most Affected Products
1. Webkul Bagisto21
2. Webkul QloApps19
3. Webkul krayin crm18
4. composer/bagisto/bagisto16
5. composer/unopim/unopim7
Recent Vulnerabilities
See more →CVE-2026-36341
CVSS 5.4medium
5/7/2026🔧 No Patch
CVE-2026-38532
CVSS 8.1high
4/14/2026🔧 No Patch
CVE-2026-38527
CVSS 8.5high
4/14/2026🔧 No Patch
CVE-2026-38530
CVSS 8.1high
4/14/2026🔧 No Patch
CVE-2026-38529
CVSS 8.8high
4/14/2026🔧 No Patch
CVE-2026-38526
CVSS 9.9critical
4/14/2026⚠ Exploited🔧 No Patch
CVE-2021-41074
CVSS 5.4medium
1/12/2026🔧 No Patch
CVE-2025-67325
CVSS 9.8critical
1/8/2026🔧 No Patch
CVE-2026-21450
CVSS 9.8EPSS 0%critical
Bagisto has SSTI in parameter that can lead to RCE
1/2/2026
CVE-2026-21451
CVSS 8.4EPSS 0%high
Bagisto has HTML Filter Bypass that Enables Stored XSS
1/2/2026
Monitor webkul in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.