---
id: CVE-2026-102630
title: >-
  UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies
  and honor the X-Forwarded-Host header without validation, allowing
  unauthenticated attackers to inject arbitrary origins into admin layout pages
summary: >-
  UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies
  and honor the X-Forwarded-Host header without validation, allowing
  unauthenticated attackers to inject arbitrary origins into admin layout pages.
  Attackers ca…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-348
vendor: unopim
product: unopim
affected:
  - unopim >= 2.0.0 < 2.0.1
  - unopim >= 2.1.0 < 2.1.1
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T16:17:06.670'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102630'
references:
  - url: 'https://github.com/unopim/unopim'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/unopim/unopim/blob/v2.1.0/bootstrap/app.php#L24'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/unopim/unopim/blob/v2.1.0/packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php#L9
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/unopim/unopim/commit/77e33618df5ba82fc9c9a32d137368e5bbe5ac9c
    label: disclosure@vulncheck.com
  - url: 'https://github.com/unopim/unopim/releases/tag/v2.0.1'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/unopim/unopim/releases/tag/v2.1.1'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/unopim-2.0.0-before-2.0.1-and-2.1.0-before-2.1.1-cache-poisoning-via-x-forwarded-host
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T16:39:33.264Z'
---

## Overview

UnoPim versions before 2.0.1 and 2.1.1 trust all connecting clients as proxies and honor the X-Forwarded-Host header without validation, allowing unauthenticated attackers to inject arbitrary origins into admin layout pages. Attackers can set X-Forwarded-Host to redirect JavaScript asset loading to their server, and when responses are cached by shared proxies, subsequent administrators execute attacker-supplied code in their authenticated sessions.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
