Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Webkul — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting Webkul. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Webkul develops e-commerce and marketplace solutions, primarily for Magento and Shopify platforms, enabling businesses to create online stores and marketplaces. Historically, their products have been vulnerable to multiple security issues, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities, as evidenced by their 8 recorded CVEs. These vulnerabilities often stem from insufficient input validation and improper access controls in their extensions. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in their products suggests a need for improved security development practices to protect their customers' environments from potential exploitation.

CVE ID Title CVSS Severity Published
CVE-2026-89268 QloApps through 1.7.0 Reflected XSS via List Filter Parameters — QloApps CWE-79 5.4 Medium 2026-09-12
CVE-2026-75498 Webkul QloApps SQL injection — QloApps CWE-89 7.2 High 2026-08-25
CVE-2026-75497 Webkul QloApps SQL injection — QloApps CWE-89 7.2 High 2026-08-25
CVE-2026-75496 Webkul QloApps improper file upload validation — QloApps CWE-434 7.2 High 2026-08-25
CVE-2026-75082 Webkul Bagisto Customer-Registration Notification Email register cross site scripting — Bagisto CWE-80 4.3 Medium 2026-08-18
CVE-2026-75081 Webkul Bagisto store behavioral workflow — Bagisto CWE-841 4.3 Medium 2026-08-17
CVE-2026-19997 Webkul Bagisto Backend Sales RMA Endpoint requests authorization — Bagisto CWE-639 4.7 Medium 2026-08-17
CVE-2026-19996 Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management — Bagisto CWE-269 4.3 Medium 2026-08-17
CVE-2026-19995 Webkul Bagisto RMA Message send-message cross site scripting — Bagisto CWE-79 3.5 Low 2026-08-17
CVE-2026-19994 Webkul Bagisto Configuration Management execute authorization — Bagisto CWE-639 6.3 Medium 2026-08-17
CVE-2026-19993 Webkul Bagisto RMA State Validation update-status behavioral workflow — Bagisto CWE-841 4.3 Medium 2026-08-17
CVE-2026-19838 Webkul Bagisto Backend Reporting Endpoint sales authorization — Bagisto CWE-639 4.3 Medium 2026-08-14
CVE-2026-19837 Webkul Bagisto Customer Search search information disclosure — Bagisto CWE-200 2.7 Low 2026-08-14
CVE-2026-19836 Webkul Bagisto Backend Customer Detail Feature view authorization — Bagisto CWE-639 4.3 Medium 2026-08-14
CVE-2026-19835 Webkul Bagisto Customer Item Deletion Endpoint access control — Bagisto CWE-284 3.8 Low 2026-08-14
CVE-2026-19834 Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization — Bagisto CWE-639 4.7 Medium 2026-08-14
CVE-2026-60120 Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php — Bagisto CWE-79 5.4 Medium 2026-07-09
CVE-2017-20262 Joomla! Component Ajax Quiz 1.8 SQL Injection — Ajax Quiz CWE-89 8.2 High 2026-06-19
CVE-2026-9506 Path Traversal Vulnerability in Bagisto — Bagisto CWE-22 - - 2026-06-08
CVE-2025-10759 Webkul QloApps CSRF Token authorization — QloApps CWE-639 5.3 Medium 2025-09-21
CVE-2025-29009 WordPress Medical Prescription Attachment Plugin for WooCommerce <= 1.2.3 - Arbitrary File Upload Vulnerability — Medical Prescription Attachment Plugin for WooCommerce CWE-434 10.0 Critical 2025-07-16
CVE-2025-6173 Webkul QloApps ajax_products_list.php sql injection — QloApps CWE-89 4.7 Medium 2025-06-17
CVE-2025-3568 Webkul Krayin CRM SVG File edit cross site scripting — Krayin CRM CWE-79 3.5 Low 2025-04-14
CVE-2025-1155 Webkul QloApps Your Location Search stores cross site scripting — QloApps CWE-79 4.3 Medium 2025-02-10
CVE-2025-1074 Webkul QloApps URL mylogout cross-site request forgery — QloApps CWE-352 4.3 Medium 2025-02-06
CVE-2024-11281 WooCommerce Point of Sale <= 6.1.0 - Insecure Direct Object Reference to Privilege Escalation via Arbitrary User Email Change — WooCommerce Point of Sale CWE-862 9.8 Critical 2024-12-25
CVE-2023-2925 Webkul krayin crm Edit Person Page 2 cross site scripting — krayin crm CWE-79 2.4 Low 2023-05-27

This page lists every published CVE security advisory associated with Webkul. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.