VulnSea

webkul has 4 CVEs on record. 4 were published in the last 90 days. The busiest recent month was September 2026 with 4. The median CVSS is 5.4 (medium). The most common weakness class is CWE-79 (3). Most affected products: qloapps (3), Aureus ERP (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
Last 90 days
4 prev 0

Weakness classes

Products

  • qloapps 3
  • Aureus ERP 1
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

webkul vulnerabilities

CVEs affecting webkul, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-93988Medium· 6.5PoC
3d ago

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files

QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email par…

Twilightwebkul · qloappsEPSS 0.37%via NVD
CVE-2026-93454Medium· 5.4
4d ago

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin

Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms end…

SunlitWebkul · Aureus ERPEPSS 0.17%via NVD
CVE-2026-92234Medium· 5.4PoC
1w ago

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute inject…

TwilightWebkul · QloAppsEPSS 0.19%via NVD
CVE-2026-89268Medium· 5.4
1w ago

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malic…

SunlitWebkul · QloAppsEPSS 0.17%via NVD
webkul vulnerabilities (CVEs) · VulnSea