Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Webkul

First CVE: May 3, 2010Active for: 16 yearsTotal CVEs: 56
39.3
VTI Score
Medium

Webkul develops a modest but prominent portfolio of open-source e-commerce, CRM, and helpdesk platforms including Bagisto, Qloapps, Krayin CRM, UnoPim, and UVDesk, which serve small-to-medium businesses and are embedded across hosted and self-managed deployments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and frequently acquire public exploit code. The exposure recurs consistently across the product line through web application weaknesses including cross-site scripting, CSRF, authorization bypasses, template injection, and code injection—patterns characteristic of PHP-based platforms with complex user input flows and access-control logic. These classes reflect the attack surface inherent to user-facing web applications where authentication, templating, and form handling are core features; defenders should treat Webkul platform updates as priority when instances are internet-reachable. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
56
Total CVEs
More Total CVEs than 99% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Webkul over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2010
16 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(8 total)

Top CVEs

Signals from CVEs in this vendor scope (56 CVEs).

56 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-30256MEDIUM
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthCont
May 11, 20236.144NOYES
CVE-2010-1659MEDIUM
Directory traversal vulnerability in the Ultimate Portfolio (com_ultimateportfolio) component 1.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in
May 3, 20105.038NOYES
CVE-2026-21450CRITICAL
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code ex
Jan 2, 20269.834NONO
CVE-2025-67325CRITICAL
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.
Jan 8, 20269.831NONO
CVE-2023-39147HIGH
An arbitrary file upload vulnerability in Uvdesk 1.1.3 allows attackers to execute arbitrary code via uploading a crafted image file.
Aug 1, 20237.831NOYES
CVE-2023-36284HIGH
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application'
Jun 23, 20237.531NOYES
CVE-2026-21446CRITICAL
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The under
Jan 2, 20269.830NONO
CVE-2026-38529HIGH
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwor
Apr 14, 20268.829NONO
CVE-2023-36289MEDIUM
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via PO
Jun 23, 20236.129NOYES
CVE-2026-21448CRITICAL
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `
Jan 2, 20269.828NONO
View all 56 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products56 CVEs
54%
36%
11%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (5.4%)
Network52 (92.9%)
Unknown1 (1.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low55 (98.2%)
High0 (0.0%)
Unknown1 (1.8%)
User Interaction
None22 (39.3%)
Unknown1 (1.8%)
Required33 (58.9%)
Privileges Required
Low18 (32.1%)
High13 (23.2%)
None24 (42.9%)
Unknown1 (1.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (56 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
5 CVEs
8.9% of CVEs· 96th percentile
ExploitDB
3 CVEs
5.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Webkul.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Webkul — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Webkul's Products

View all 5 CNAs →

Top CWEs