QloApps
Webkul · 15 CVEs
QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms
Oct 6, 2026
QloApps through 1.7.0 Reflected XSS via Length of Stay Fields
Sep 30, 2026
QloApps through 1.7.0 Reflected XSS via Room Type Editor
Sep 30, 2026
QloApps through 1.7.0 Reflected XSS via exceptions field
Sep 30, 2026
QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters
Sep 30, 2026
QloApps through 1.7.0 Arbitrary File Read via getEmailHTML
Sep 19, 2026
QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors
Sep 15, 2026
QloApps through 1.7.0 Reflected XSS via List Filter Parameters
Sep 12, 2026
Webkul QloApps SQL injection
Aug 25, 2026
Webkul QloApps SQL injection
Aug 25, 2026
Webkul QloApps improper file upload validation
Aug 25, 2026
A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a…
Jan 12, 2026
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticate…
Jan 8, 2026
Webkul QloApps CSRF Token authorization
Sep 21, 2025
Webkul QloApps ajax_products_list.php sql injection
Jun 17, 2025
Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or ot…
Feb 18, 2025
Webkul QloApps Your Location Search stores cross site scripting
Feb 10, 2025
Webkul QloApps URL mylogout cross-site request forgery
Feb 6, 2025
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via upload…
Jul 25, 2024
An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter.
Jan 17, 2024
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain…
Jun 23, 2023
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain…
Jun 23, 2023
An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain…
Jun 23, 2023
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_…
Jun 23, 2023
Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive informa…
May 11, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-105836 | QloApps through 1.7.0 Authorization Bypass via ajaxProcessBulkUpdateRooms | MEDIUM | n/a | Oct 6, 2026 |
| CVE-2026-103590 | QloApps through 1.7.0 Reflected XSS via Length of Stay Fields | MEDIUM | 0.19% | Sep 30, 2026 |
| CVE-2026-103589 | QloApps through 1.7.0 Reflected XSS via Room Type Editor | MEDIUM | 0.19% | Sep 30, 2026 |
| CVE-2026-103588 | QloApps through 1.7.0 Reflected XSS via exceptions field | MEDIUM | 0.18% | Sep 30, 2026 |
| CVE-2026-103587 | QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters | MEDIUM | 0.18% | Sep 30, 2026 |
| CVE-2026-93988 | QloApps through 1.7.0 Arbitrary File Read via getEmailHTML | HIGH | 0.55% | Sep 19, 2026 |
| CVE-2026-92234 | QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors | MEDIUM | 0.31% | Sep 15, 2026 |
| CVE-2026-89268 | QloApps through 1.7.0 Reflected XSS via List Filter Parameters | MEDIUM | 0.30% | Sep 12, 2026 |
| CVE-2026-75498 | Webkul QloApps SQL injection | HIGH | 0.81% | Aug 25, 2026 |
| CVE-2026-75497 | Webkul QloApps SQL injection | HIGH | 0.81% | Aug 25, 2026 |
| CVE-2026-75496 | Webkul QloApps improper file upload validation | HIGH | 0.98% | Aug 25, 2026 |
| CVE-2021-41074 | A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document. | MEDIUM | 0.14% | Jan 12, 2026 |
| CVE-2025-67325 | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execu… | CRITICAL | 0.91% | Jan 8, 2026 |
| CVE-2025-10759 | Webkul QloApps CSRF Token authorization | MEDIUM | 0.35% | Sep 21, 2025 |
| CVE-2025-6173 | Webkul QloApps ajax_products_list.php sql injection | MEDIUM | 0.57% | Jun 17, 2025 |
| CVE-2025-26058 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application app… | MEDIUM | 0.22% | Feb 18, 2025 |
| CVE-2025-1155 | Webkul QloApps Your Location Search stores cross site scripting | MEDIUM | 0.54% | Feb 10, 2025 |
| CVE-2025-1074 | Webkul QloApps URL mylogout cross-site request forgery | MEDIUM | 0.33% | Feb 6, 2025 |
| CVE-2024-40318 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. | HIGH | 1.18% | Jul 25, 2024 |
| CVE-2023-36235 | An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. | MEDIUM | 0.66% | Jan 17, 2024 |
| CVE-2023-36289 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then imperso… | MEDIUM | 1.17% | Jun 23, 2023 |
| CVE-2023-36288 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then imperso… | MEDIUM | 0.44% | Jun 23, 2023 |
| CVE-2023-36287 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then imperso… | MEDIUM | 1.20% | Jun 23, 2023 |
| CVE-2023-36284 | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypa… | HIGH | 3.16% | Jun 23, 2023 |
| CVE-2023-30256 | Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create param… | MEDIUM | 9.05% | May 11, 2023 |
Showing 1 to 15 of 15 CVEs