Webkul develops a modest but prominent portfolio of open-source e-commerce, CRM, and helpdesk platforms including Bagisto, Qloapps, Krayin CRM, UnoPim, and UVDesk, which serve small-to-medium businesses and are embedded across hosted and self-managed deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code. The exposure recurs consistently across the product line through web application weaknesses including cross-site scripting, CSRF, authorization bypasses, template injection, and code injection—patterns characteristic of PHP-based platforms with complex user input flows and access-control logic. These classes reflect the attack surface inherent to user-facing web applications where authentication, templating, and form handling are core features; defenders should treat Webkul platform updates as priority when instances are internet-reachable. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webkul over time
Signals from CVEs in this vendor scope (56 CVEs).
56 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-30256MEDIUM Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthCont | May 11, 2023 | 6.1 | 44 | NO | YES |
CVE-2010-1659MEDIUM Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in | May 3, 2010 | 5.0 | 38 | NO | YES |
CVE-2026-21450CRITICAL Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code ex | Jan 2, 2026 | 9.8 | 34 | NO | NO |
CVE-2025-67325CRITICAL Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution. | Jan 8, 2026 | 9.8 | 31 | NO | NO |
CVE-2023-39147HIGH An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file. | Aug 1, 2023 | 7.8 | 31 | NO | YES |
CVE-2023-36284HIGH An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application' | Jun 23, 2023 | 7.5 | 31 | NO | YES |
CVE-2026-21446CRITICAL Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The under | Jan 2, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-38529HIGH A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwor | Apr 14, 2026 | 8.8 | 29 | NO | NO |
CVE-2023-36289MEDIUM An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via PO | Jun 23, 2023 | 6.1 | 29 | NO | YES |
CVE-2026-21448CRITICAL Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the ` | Jan 2, 2026 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (56 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webkul.
Media articles that mention a CVE ID that affects a product developed by Webkul — matched by CVE ID, not by vendor name.