Where
-Infinity
0

Webkul krayin crmXSS

Risk 34
Severity
5.4
First published (updated )

Webkul krayin crmA Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of …

Risk 60
Severity
8.1
First published (updated )

Webkul krayin crmSSRF

Risk 55
Severity
8.5
First published (updated )

Webkul krayin crmA Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of W…

Risk 60
Severity
8.1
First published (updated )

Webkul krayin crmA Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Kr…

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Webkul krayin crmMalicious File Upload

Risk 100
Severity
9.9
First published (updated )

QloApps QloApps hotel eCommerceCSRF

Risk 34
Severity
5.4
First published (updated )

QloApps QloAppsMalicious File Upload

Risk 86
Severity
9.8
First published (updated )

bagisto/bagistoBagisto has SSTI in parameter that can lead to RCE

Risk 61
Severity
9.8
EPSS
0.10%
First published (updated )

Bagisto BagistoBagisto has HTML Filter Bypass that Enables Stored XSS

Risk 37
Severity
8.4
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pypi/bagistoBagisto has SSTI via first and last name from low-privilege user (not admin)

Risk 56
Severity
8.8
EPSS
0.06%
First published (updated )

npm/bagistoBagisto has Normal & Blind SSTI from low-privilege user when ordering product

Risk 61
Severity
9.8
EPSS
0.36%
First published (updated )

laravel/bagistoBagisto has IDOR in Customer Order Reorder Functionality

Risk 35
Severity
7.1
EPSS
0.03%
First published (updated )

npm/bagistoBagisto Missing Authentication on Installer API Endpoints

Risk 61
Severity
9.8
EPSS
0.29%
First published (updated )

Bagisto Bagistobagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (SVG)

Risk 43
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Bagisto Bagistobagisto - Cross Site Scripting (XSS) in Create New Customer

Risk 43
Severity
6.9
First published (updated )

Bagisto Bagistobagisto - Server Side Template Injection (SSTI) in Product Description

Risk 61
Severity
6.8
First published (updated )

Bagisto Bagistobagisto - CSV Formula Injection in Create New Product

Risk 75
Severity
9.1
First published (updated )

composer/bagisto/bagistobagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (HTML)

Risk 43
Severity
6.9
First published (updated )

Bagisto BagistoXSS

Risk 62
Severity
8.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Webkul BagistoCommand Injection

Risk 40
Severity
6.5
First published (updated )

Webkul QloAppsWebkul QloApps CSRF Token authorization

Risk 28
Severity
5.5
First published (updated )

UnoPim UnoPimUnoPim Quick Export feature is vulnerable to CSV injection

Risk 77
Severity
8.8
First published (updated )

UnoPim UnoPimunopim/unopim allows unauthorized product deletion via mass-delete endpoint

Risk 60
Severity
8.1
First published (updated )

composer/unopim/unopimUnoPim vulnerable to CSRF on Product edit feature and creation of other types

Risk 39
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/unopim/unopimUnoPim vulnerable to remote code execution through Arbitrary File upload

Risk 79
Severity
8.8
First published (updated )

composer/unopim/unopimUnoPim Stored XSS via SVG MIME/Sanitizer Bypass

Risk 71
Severity
8
First published (updated )

Webkul Medical Prescription Attachment Plugin for WooCommerceWordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload Vulnerability

Risk 87
Severity
10
First published (updated )

Webkul QloAppsWebkul QloApps ajax_products_list.php sql injection

Risk 49
Severity
2
EPSS
0.03%
First published (updated )

Webkul BagistoReflected Cross-Site Scripting (XSS) in Bagisto

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203