Search
Find a vulnerability
Search criteria
176 vulnerabilities by Webkul
CVE-2026-103590 (GCVE-0-2026-103590)
Vulnerability from nvd – Published: 2026-09-30 23:02 – Updated: 2026-10-01 14:24
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Length of Stay Fields
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:24 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1899 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/7ed467d… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/ad… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103590",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:24:42.160599Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:24:50.123Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"admin/themes/default/template/controllers/products/lengthofstay.tpl"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor\u0027s length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim\u0027s administrative session."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:35.019Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1899",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1899"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/lengthofstay.tpl"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Length of Stay Fields",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-length-of-stay-fields"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Length of Stay Fields",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103590",
"datePublished": "2026-09-30T23:02:35.019Z",
"dateReserved": "2026-09-30T22:32:08.114Z",
"dateUpdated": "2026-10-01T14:24:50.123Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103589 (GCVE-0-2026-103589)
Vulnerability from nvd – Published: 2026-09-30 23:02 – Updated: 2026-10-01 18:57
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Room Type Editor
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:57 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1899 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/7ed467d… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/ad… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103589",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:57:33.060269Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:57:50.422Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"admin/themes/default/template/controllers/products/configuration.tpl"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim\u0027s administrative session."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:34.299Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1899",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1899"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/configuration.tpl"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Room Type Editor",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-room-type-editor"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Room Type Editor",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103589",
"datePublished": "2026-09-30T23:02:34.299Z",
"dateReserved": "2026-09-30T22:32:07.731Z",
"dateUpdated": "2026-10-01T18:57:50.422Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103588 (GCVE-0-2026-103588)
Vulnerability from nvd – Published: 2026-09-30 23:02 – Updated: 2026-09-30 23:02
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via exceptions field
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.
Severity
5.4 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1899 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/7ed467d… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/co… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"controllers/admin/AdminModulesPositionsController.php"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator\u0027s session when the victim follows the link."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:33.566Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1899",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1899"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/controllers/admin/AdminModulesPositionsController.php"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via exceptions field",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-exceptions-field"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via exceptions field",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103588",
"datePublished": "2026-09-30T23:02:33.566Z",
"dateReserved": "2026-09-30T22:32:07.355Z",
"dateUpdated": "2026-09-30T23:02:33.566Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103587 (GCVE-0-2026-103587)
Vulnerability from nvd – Published: 2026-09-30 23:02 – Updated: 2026-10-01 15:40
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:39 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1884 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/1d06fd3… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/mo… | technical-description |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/mo… | technical-description |
| https://hackmd.io/@leediay/reflected-xss-qloapps-… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103587",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:39:58.785247Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:40:35.776Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/reflected-xss-qloapps-via-booking-now"
},
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator\u0027s session when the victim follows the link."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:32.852Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1884",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1884"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/1d06fd302a935d68203dbdb341d89482621769d7"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/views/templates/admin/hotel_rooms_booking/helpers/view/_partials/booking-rooms.tpl"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/reflected-xss-qloapps-via-booking-now"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-book-now-search-parameters"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103587",
"datePublished": "2026-09-30T23:02:32.852Z",
"dateReserved": "2026-09-30T22:31:58.851Z",
"dateUpdated": "2026-10-01T15:40:35.776Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101139 (GCVE-0-2026-101139)
Vulnerability from nvd – Published: 2026-09-28 19:00 – Updated: 2026-09-29 16:30 X_Open Source
VLAI
EPSS
VEX
Title
Webkul Bagisto Invoice Mass Status Update state authorization
Summary
A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: "[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch."
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 19:26 UTC
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410992 | vdb-entry |
| https://vuldb.com/vuln/410992/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101139 | third-party-advisory |
| https://vuldb.com/submit/894633 | third-party-advisory |
| https://drive.google.com/file/d/1ymuUIZJaHZ7oDyeb… | exploit |
| https://github.com/bagisto/bagisto/pull/11493 | issue-trackingpatch |
| https://github.com/bagisto/bagisto/commit/2c34b94… | patch |
| https://github.com/bagisto/bagisto/releases/tag/v… | patch |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Bagisto |
Affected:
2.4.0
Affected: 2.4.1 Affected: 2.4.2 Affected: 2.4.3 Affected: 2.4.4 Affected: 2.4.5 Affected: 2.4.6 Affected: 2.5.0-beta1 Affected: 2.5.0-beta2 Affected: 2.5.0-beta3 Affected: 2.5.0-beta4 Unaffected: 2.5.0-beta5 cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101139",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T19:26:03.665583Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T19:26:19.616Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*"
],
"modules": [
"Invoice Mass Status Update"
],
"product": "Bagisto",
"vendor": "Webkul",
"versions": [
{
"status": "affected",
"version": "2.4.0"
},
{
"status": "affected",
"version": "2.4.1"
},
{
"status": "affected",
"version": "2.4.2"
},
{
"status": "affected",
"version": "2.4.3"
},
{
"status": "affected",
"version": "2.4.4"
},
{
"status": "affected",
"version": "2.4.5"
},
{
"status": "affected",
"version": "2.4.6"
},
{
"status": "affected",
"version": "2.5.0-beta1"
},
{
"status": "affected",
"version": "2.5.0-beta2"
},
{
"status": "affected",
"version": "2.5.0-beta3"
},
{
"status": "affected",
"version": "2.5.0-beta4"
},
{
"status": "unaffected",
"version": "2.5.0-beta5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ciphersecuritylabs (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: \"[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch.\""
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 2.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 2.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 3.3,
"vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T16:30:39.149Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410992 | Webkul Bagisto Invoice Mass Status Update state authorization",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/410992"
},
{
"name": "VDB-410992 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410992/cti"
},
{
"name": "CVE-2026-101139 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101139"
},
{
"name": "Submit #894633 | Webkul Bagisto 2.4.6 Missing Authorization",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894633"
},
{
"tags": [
"exploit"
],
"url": "https://drive.google.com/file/d/1ymuUIZJaHZ7oDyebyLKn9RfRPAzDKMmm/view"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/bagisto/bagisto/pull/11493"
},
{
"tags": [
"patch"
],
"url": "https://github.com/bagisto/bagisto/commit/2c34b94d0313824ce98efee8aef8ee141d9b89d0"
},
{
"tags": [
"patch"
],
"url": "https://github.com/bagisto/bagisto/releases/tag/v2.5.0-beta5"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-28T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-29T18:35:30.000Z",
"value": "VulDB entry last update"
}
],
"title": "Webkul Bagisto Invoice Mass Status Update state authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101139",
"datePublished": "2026-09-28T19:00:11.265Z",
"dateReserved": "2026-09-28T07:42:38.014Z",
"dateUpdated": "2026-09-29T16:30:39.149Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97062 (GCVE-0-2026-97062)
Vulnerability from nvd – Published: 2026-09-24 13:52 – Updated: 2026-09-24 14:58
VLAI
EPSS
VEX
Title
Aureus ERP through 1.6.0 Stored XSS via SVG File Upload
Summary
Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 14:57 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/pull/1574 | patchissue-tracking |
| https://hackmd.io/@leediay/stored-xss-via-svg-upl… | third-party-advisory |
| https://github.com/aureuserp/aureuserp/blob/b33fa… | technical-description |
| https://github.com/aureuserp/aureuserp/blob/b33fa… | technical-description |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , ≤ 1.6.0
(semver)
|
Date Public
2026-09-22 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97062",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T14:57:04.998484Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:58:04.897Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-22T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application\u0027s origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:23:31.614Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1574",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1574"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-svg-file-upload"
}
],
"title": "Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97062",
"datePublished": "2026-09-24T13:52:02.569Z",
"dateReserved": "2026-09-23T23:51:32.671Z",
"dateUpdated": "2026-09-24T14:58:04.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95655 (GCVE-0-2026-95655)
Vulnerability from nvd – Published: 2026-09-22 15:24 – Updated: 2026-09-28 15:29
VLAI
EPSS
VEX
Title
Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel
Summary
Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 17:22 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/commit/d3d… | patch |
| https://github.com/aureuserp/aureuserp/pull/1382 | patchissue-tracking |
| https://github.com/aureuserp/aureuserp/blob/v1.4.… | technical-description |
| https://github.com/aureuserp/aureuserp/blob/v1.4.… | technical-description |
| https://hackmd.io/@leediay/idor-chatter-messager-aureus | third-party-advisory |
| https://github.com/aureuserp/aureuserp/releases/t… | release-notes |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-b… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , < 1.5.0
(semver)
Unaffected: 1.5.0 (semver) |
Date Public
2026-07-06 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95655",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T17:22:41.493052Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T17:44:08.806Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThan": "1.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.5.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-07-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T15:29:10.232Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/aureuserp/aureuserp/commit/d3d5ac20ec544e97636490db6f86a391c04ce899"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1382"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.4.0/plugins/webkul/chatter/src/Livewire/ChatterPanel.php#L503"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.4.0/plugins/webkul/chatter/src/Livewire/ChatterPanel.php#L685"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/idor-chatter-messager-aureus"
},
{
"name": "aureuserp v1.5.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/aureuserp/aureuserp/releases/tag/v1.5.0"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-before-1.5.0-unscoped-message-access-via-chatterpanel"
}
],
"title": "Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-95655",
"datePublished": "2026-09-22T15:24:13.836Z",
"dateReserved": "2026-09-22T12:29:08.887Z",
"dateUpdated": "2026-09-28T15:29:10.232Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94387 (GCVE-0-2026-94387)
Vulnerability from nvd – Published: 2026-09-21 13:43 – Updated: 2026-09-28 15:29
VLAI
EPSS
VEX
Title
Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log
Summary
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 15:17 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/commit/57c… | patch |
| https://github.com/aureuserp/aureuserp/pull/1465 | patchissue-tracking |
| https://github.com/aureuserp/aureuserp/blob/v1.5.… | technical-description |
| https://github.com/aureuserp/aureuserp/blob/v1.5.… | technical-description |
| https://hackmd.io/@leediay/stored-xss-aureuserp-chatter | third-party-advisory |
| https://github.com/aureuserp/aureuserp/releases/t… | release-notes |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-b… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , < 1.6.0
(semver)
Unaffected: 1.6.0 (semver) |
Date Public
2026-08-05 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94387",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T15:17:05.399855Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T15:17:23.071Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThan": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.6.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-08-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record\u0027s Chatter panel."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T15:29:08.702Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c"
},
{
"name": "PR #1465 chatter-security",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1465"
},
{
"name": "Unescaped old_value render at v1.5.0",
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165"
},
{
"name": "Unescaped new_value render at v1.5.0",
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182"
},
{
"name": "Reporter write-up",
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/stored-xss-aureuserp-chatter"
},
{
"name": "aureuserp v1.6.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-before-1.6.0-stored-xss-via-chatter-field-change-log"
}
],
"title": "Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-94387",
"datePublished": "2026-09-21T13:43:36.234Z",
"dateReserved": "2026-09-21T13:09:30.374Z",
"dateUpdated": "2026-09-28T15:29:08.702Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93988 (GCVE-0-2026-93988)
Vulnerability from nvd – Published: 2026-09-19 22:58 – Updated: 2026-09-27 14:29
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Arbitrary File Read via getEmailHTML
Summary
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 14:13 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1719 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/8015495… | patch |
| https://github.com/Qloapps/QloApps/blob/f768898c2… | technical-description |
| https://hackmd.io/@leediay/qloapps-arbitrary-file… | third-party-advisoryexploit |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-05-28 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93988",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T14:13:53.418469Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T14:14:01.593Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/webkul/qloapps",
"product": "qloapps",
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-05-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T14:29:46.872Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub PR #1719",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1719"
},
{
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715"
},
{
"name": "getEmailHTML at v1.7.0",
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/f768898c20c43cb0733a6099e390e5be71631393/controllers/admin/AdminTranslationsController.php#L3038-L3051"
},
{
"tags": [
"third-party-advisory",
"exploit"
],
"url": "https://hackmd.io/@leediay/qloapps-arbitrary-file-read-via-path-traversal"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-arbitrary-file-read-via-getemailhtml"
}
],
"title": "QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93988",
"datePublished": "2026-09-19T22:58:09.912Z",
"dateReserved": "2026-09-19T10:55:49.093Z",
"dateUpdated": "2026-09-27T14:29:46.872Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93454 (GCVE-0-2026-93454)
Vulnerability from nvd – Published: 2026-09-17 23:25 – Updated: 2026-09-22 01:59
VLAI
EPSS
VEX
Title
Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
Summary
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 01:59 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/pull/1562 | patchissue-tracking |
| https://hackmd.io/@leediay/stored-xss-aureus-via-… | exploit |
| https://github.com/aureuserp/aureuserp/blob/v1.6.… | technical-description |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , ≤ 1.6.0
(semver)
|
Date Public
2026-09-11 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93454",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T01:59:33.777189Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T01:59:49.437Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://packagist.org",
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"repo": "https://github.com/aureuserp/aureuserp",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T23:25:13.531Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1562"
},
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/stored-xss-aureus-via-payment-term"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.6.0/plugins/webkul/accounts/src/Filament/Resources/PaymentTermResource/Schemas/PaymentTermInfolist.php#L59"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP through 1.6.0 Stored XSS via Payment Term Note",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-payment-term-note"
}
],
"title": "Aureus ERP through 1.6.0 Stored XSS via Payment Term Note",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93454",
"datePublished": "2026-09-17T23:25:13.531Z",
"dateReserved": "2026-09-17T22:45:31.668Z",
"dateUpdated": "2026-09-22T01:59:49.437Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92234 (GCVE-0-2026-92234)
Vulnerability from nvd – Published: 2026-09-15 20:56 – Updated: 2026-09-16 18:02
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors
Summary
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:01 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1796 | patchissue-tracking |
| https://github.com/Qloapps/QloApps/commit/54a3b30… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/mo… | technical-description |
| https://hackmd.io/@leediay/r1aoFrMFGl | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-08-07 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92234",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:01:04.208790Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:02:11.766Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/r1aoFrMFGl"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"modules/hotelreservationsystem/controllers/admin/AdminHotelfeaturesController.php"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-08-07T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T20:56:46.515Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Fix PR #1796",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/Qloapps/QloApps/pull/1796"
},
{
"name": "Merge commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/54a3b30e4e5c2d6b224dc8fe55e75db173064b91"
},
{
"name": "Unescaped error paths at v1.7.0",
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelfeaturesController.php"
},
{
"name": "Reporter write-up",
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/r1aoFrMFGl"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-hotel-feature-validation-errors"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92234",
"datePublished": "2026-09-15T20:56:46.515Z",
"dateReserved": "2026-09-15T19:27:24.634Z",
"dateUpdated": "2026-09-16T18:02:11.766Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89268 (GCVE-0-2026-89268)
Vulnerability from nvd – Published: 2026-09-12 01:50 – Updated: 2026-09-14 18:33
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via List Filter Parameters
Summary
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-14 18:33 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1801 | patchissue-tracking |
| https://github.com/Qloapps/QloApps/commit/153ec1c… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/ad… | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-08-24 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89268",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T18:33:32.753327Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T18:33:56.410Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-08-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim\u0027s session to read administrative data and perform actions."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-12T01:50:33.852Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1801",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/Qloapps/QloApps/pull/1801"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/153ec1c8567798bd99155098ecc0a340e38f25bf"
},
{
"name": "Unescaped filter values in list_header.tpl at v1.7.0",
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/helpers/list/list_header.tpl"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via List Filter Parameters",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-list-filter-parameters"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via List Filter Parameters",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-89268",
"datePublished": "2026-09-12T01:50:33.852Z",
"dateReserved": "2026-09-11T10:52:56.669Z",
"dateUpdated": "2026-09-14T18:33:56.410Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75498 (GCVE-0-2026-75498)
Vulnerability from nvd – Published: 2026-08-25 16:37 – Updated: 2026-08-25 18:06
VLAI
EPSS
VEX
Title
Webkul QloApps SQL injection
Summary
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-18 14:33 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
References
3 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1783/chan… | patch |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-75498 | vdb-entry |
Impacted products
Date Public
2026-08-13 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75498",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:06:10.525444Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:06:22.590Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThan": "123c97c",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "123c97c"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "leediay153"
}
],
"datePublic": "2026-08-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the \u0027bo_query\u0027 parameter in the \u0027Address.php\u0027 file. Fixed in 123c97c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-75498",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T14:33:09.059645Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T16:37:43.725Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-75498"
}
],
"title": "Webkul QloApps SQL injection"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-75498",
"datePublished": "2026-08-25T16:37:43.725Z",
"dateReserved": "2026-08-17T20:16:01.457Z",
"dateUpdated": "2026-08-25T18:06:22.590Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75497 (GCVE-0-2026-75497)
Vulnerability from nvd – Published: 2026-08-25 16:37 – Updated: 2026-08-25 18:05
VLAI
EPSS
VEX
Title
Webkul QloApps SQL injection
Summary
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-18 14:32 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
References
3 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1783/chan… | patch |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-75497 | vdb-entry |
Impacted products
Date Public
2026-08-13 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75497",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:05:50.184882Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:05:58.384Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThan": "123c97c",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "123c97c"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "leediay153"
}
],
"datePublic": "2026-08-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the \u0027bo_query\u0027 parameter in the \u0027CustomerMessage.php\u0027 file. Fixed in 123c97c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-75497",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T14:32:30.238898Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T16:37:10.271Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-75497"
}
],
"title": "Webkul QloApps SQL injection"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-75497",
"datePublished": "2026-08-25T16:37:10.271Z",
"dateReserved": "2026-08-17T20:16:01.457Z",
"dateUpdated": "2026-08-25T18:05:58.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75496 (GCVE-0-2026-75496)
Vulnerability from nvd – Published: 2026-08-25 16:36 – Updated: 2026-08-25 18:05
VLAI
EPSS
VEX
Title
Webkul QloApps improper file upload validation
Summary
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-17 20:27 UTC
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
References
3 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1801/comm… | patch |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-75496 | vdb-entry |
Impacted products
Date Public
2026-07-20 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75496",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:05:24.426739Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:05:38.099Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThan": "153ec1c",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "153ec1c"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "leediay153"
}
],
"datePublic": "2026-07-20T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-75496",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-17T20:27:36.847949Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T16:36:42.577Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1801/commits/153ec1c8567798bd99155098ecc0a340e38f25bf"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-75496"
}
],
"title": "Webkul QloApps improper file upload validation"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-75496",
"datePublished": "2026-08-25T16:36:42.577Z",
"dateReserved": "2026-08-17T20:16:01.457Z",
"dateUpdated": "2026-08-25T18:05:38.099Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103590 (GCVE-0-2026-103590)
Vulnerability from cvelistv5 – Published: 2026-09-30 23:02 – Updated: 2026-10-01 14:24
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Length of Stay Fields
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim's administrative session.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 14:24 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1899 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/7ed467d… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/ad… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103590",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T14:24:42.160599Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T14:24:50.123Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"admin/themes/default/template/controllers/products/lengthofstay.tpl"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor\u0027s length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing arbitrary JavaScript in the victim\u0027s administrative session."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:35.019Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1899",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1899"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/lengthofstay.tpl"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Length of Stay Fields",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-length-of-stay-fields"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Length of Stay Fields",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103590",
"datePublished": "2026-09-30T23:02:35.019Z",
"dateReserved": "2026-09-30T22:32:08.114Z",
"dateUpdated": "2026-10-01T14:24:50.123Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103589 (GCVE-0-2026-103589)
Vulnerability from cvelistv5 – Published: 2026-09-30 23:02 – Updated: 2026-10-01 18:57
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Room Type Editor
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim's administrative session.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 18:57 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1899 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/7ed467d… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/ad… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103589",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T18:57:33.060269Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T18:57:50.422Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"admin/themes/default/template/controllers/products/configuration.tpl"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute arbitrary JavaScript in the victim\u0027s administrative session."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:34.299Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1899",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1899"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/controllers/products/configuration.tpl"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Room Type Editor",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-room-type-editor"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Room Type Editor",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103589",
"datePublished": "2026-09-30T23:02:34.299Z",
"dateReserved": "2026-09-30T22:32:07.731Z",
"dateUpdated": "2026-10-01T18:57:50.422Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103588 (GCVE-0-2026-103588)
Vulnerability from cvelistv5 – Published: 2026-09-30 23:02 – Updated: 2026-09-30 23:02
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via exceptions field
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim follows the link.
Severity
5.4 (Medium)
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1899 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/7ed467d… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/co… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"controllers/admin/AdminModulesPositionsController.php"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator\u0027s session when the victim follows the link."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:33.566Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1899",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1899"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/7ed467d911086b190180d7f297e3b15ba31e82d5"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/controllers/admin/AdminModulesPositionsController.php"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via exceptions field",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-exceptions-field"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via exceptions field",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103588",
"datePublished": "2026-09-30T23:02:33.566Z",
"dateReserved": "2026-09-30T22:32:07.355Z",
"dateUpdated": "2026-09-30T23:02:33.566Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-103587 (GCVE-0-2026-103587)
Vulnerability from cvelistv5 – Published: 2026-09-30 23:02 – Updated: 2026-10-01 15:40
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters
Summary
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator's session when the victim follows the link.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-10-01 15:39 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1884 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/1d06fd3… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/mo… | technical-description |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/mo… | technical-description |
| https://hackmd.io/@leediay/reflected-xss-qloapps-… | technical-description |
| https://hackmd.io/@leediay/four-reflected-xss-qloapps | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-09-30 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-103587",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-10-01T15:39:58.785247Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-10-01T15:40:35.776Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/reflected-xss-qloapps-via-booking-now"
},
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these parameters that executes in an authenticated administrator\u0027s session when the victim follows the link."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-30T23:02:32.852Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1884",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1884"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/1d06fd302a935d68203dbdb341d89482621769d7"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelRoomsBookingController.php"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/views/templates/admin/hotel_rooms_booking/helpers/view/_partials/booking-rooms.tpl"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/reflected-xss-qloapps-via-booking-now"
},
{
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/four-reflected-xss-qloapps"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-book-now-search-parameters"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Book Now Search Parameters",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-103587",
"datePublished": "2026-09-30T23:02:32.852Z",
"dateReserved": "2026-09-30T22:31:58.851Z",
"dateUpdated": "2026-10-01T15:40:35.776Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-101139 (GCVE-0-2026-101139)
Vulnerability from cvelistv5 – Published: 2026-09-28 19:00 – Updated: 2026-09-29 16:30 X_Open Source
VLAI
EPSS
VEX
Title
Webkul Bagisto Invoice Mass Status Update state authorization
Summary
A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: "[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch."
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-28 19:26 UTC
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410992 | vdb-entry |
| https://vuldb.com/vuln/410992/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101139 | third-party-advisory |
| https://vuldb.com/submit/894633 | third-party-advisory |
| https://drive.google.com/file/d/1ymuUIZJaHZ7oDyeb… | exploit |
| https://github.com/bagisto/bagisto/pull/11493 | issue-trackingpatch |
| https://github.com/bagisto/bagisto/commit/2c34b94… | patch |
| https://github.com/bagisto/bagisto/releases/tag/v… | patch |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Bagisto |
Affected:
2.4.0
Affected: 2.4.1 Affected: 2.4.2 Affected: 2.4.3 Affected: 2.4.4 Affected: 2.4.5 Affected: 2.4.6 Affected: 2.5.0-beta1 Affected: 2.5.0-beta2 Affected: 2.5.0-beta3 Affected: 2.5.0-beta4 Unaffected: 2.5.0-beta5 cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101139",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T19:26:03.665583Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T19:26:19.616Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*"
],
"modules": [
"Invoice Mass Status Update"
],
"product": "Bagisto",
"vendor": "Webkul",
"versions": [
{
"status": "affected",
"version": "2.4.0"
},
{
"status": "affected",
"version": "2.4.1"
},
{
"status": "affected",
"version": "2.4.2"
},
{
"status": "affected",
"version": "2.4.3"
},
{
"status": "affected",
"version": "2.4.4"
},
{
"status": "affected",
"version": "2.4.5"
},
{
"status": "affected",
"version": "2.4.6"
},
{
"status": "affected",
"version": "2.5.0-beta1"
},
{
"status": "affected",
"version": "2.5.0-beta2"
},
{
"status": "affected",
"version": "2.5.0-beta3"
},
{
"status": "affected",
"version": "2.5.0-beta4"
},
{
"status": "unaffected",
"version": "2.5.0-beta5"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ciphersecuritylabs (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: \"[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch.\""
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 2.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 2.7,
"baseSeverity": "LOW",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 3.3,
"vectorString": "AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-862",
"description": "Missing Authorization",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-863",
"description": "Incorrect Authorization",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-29T16:30:39.149Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410992 | Webkul Bagisto Invoice Mass Status Update state authorization",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/410992"
},
{
"name": "VDB-410992 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410992/cti"
},
{
"name": "CVE-2026-101139 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101139"
},
{
"name": "Submit #894633 | Webkul Bagisto 2.4.6 Missing Authorization",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/894633"
},
{
"tags": [
"exploit"
],
"url": "https://drive.google.com/file/d/1ymuUIZJaHZ7oDyebyLKn9RfRPAzDKMmm/view"
},
{
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/bagisto/bagisto/pull/11493"
},
{
"tags": [
"patch"
],
"url": "https://github.com/bagisto/bagisto/commit/2c34b94d0313824ce98efee8aef8ee141d9b89d0"
},
{
"tags": [
"patch"
],
"url": "https://github.com/bagisto/bagisto/releases/tag/v2.5.0-beta5"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-28T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-28T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-29T18:35:30.000Z",
"value": "VulDB entry last update"
}
],
"title": "Webkul Bagisto Invoice Mass Status Update state authorization",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101139",
"datePublished": "2026-09-28T19:00:11.265Z",
"dateReserved": "2026-09-28T07:42:38.014Z",
"dateUpdated": "2026-09-29T16:30:39.149Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97062 (GCVE-0-2026-97062)
Vulnerability from cvelistv5 – Published: 2026-09-24 13:52 – Updated: 2026-09-24 14:58
VLAI
EPSS
VEX
Title
Aureus ERP through 1.6.0 Stored XSS via SVG File Upload
Summary
Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application's origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-24 14:57 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/pull/1574 | patchissue-tracking |
| https://hackmd.io/@leediay/stored-xss-via-svg-upl… | third-party-advisory |
| https://github.com/aureuserp/aureuserp/blob/b33fa… | technical-description |
| https://github.com/aureuserp/aureuserp/blob/b33fa… | technical-description |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , ≤ 1.6.0
(semver)
|
Date Public
2026-09-22 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97062",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-24T14:57:04.998484Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:58:04.897Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-22T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allowing authenticated users to upload malicious SVG files containing JavaScript. Attackers can craft SVG files with script elements that execute in the application\u0027s origin when the file URL is opened directly, enabling session cookie theft and CSRF token exfiltration."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:23:31.614Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1574",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1574"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/stored-xss-via-svg-upload-aureuserp"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Resources/CompanyResource/Schemas/CompanyForm.php#L196-L200"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/b33fa04643a936885f83b5ad39a62260ef27a7a0/plugins/webkul/support/src/Filament/Clusters/Settings/Pages/ManageBranding.php#L65-L84"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-svg-file-upload"
}
],
"title": "Aureus ERP through 1.6.0 Stored XSS via SVG File Upload",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-97062",
"datePublished": "2026-09-24T13:52:02.569Z",
"dateReserved": "2026-09-23T23:51:32.671Z",
"dateUpdated": "2026-09-24T14:58:04.897Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95655 (GCVE-0-2026-95655)
Vulnerability from cvelistv5 – Published: 2026-09-22 15:24 – Updated: 2026-09-28 15:29
VLAI
EPSS
VEX
Title
Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel
Summary
Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system.
Severity
SSVC
Exploitation: none
Automatable: no
Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 17:22 UTC
CWE
- CWE-639 - Authorization Bypass Through User-Controlled Key
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/commit/d3d… | patch |
| https://github.com/aureuserp/aureuserp/pull/1382 | patchissue-tracking |
| https://github.com/aureuserp/aureuserp/blob/v1.4.… | technical-description |
| https://github.com/aureuserp/aureuserp/blob/v1.4.… | technical-description |
| https://hackmd.io/@leediay/idor-chatter-messager-aureus | third-party-advisory |
| https://github.com/aureuserp/aureuserp/releases/t… | release-notes |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-b… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , < 1.5.0
(semver)
Unaffected: 1.5.0 (semver) |
Date Public
2026-07-06 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-95655",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T17:22:41.493052Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T17:44:08.806Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThan": "1.5.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.5.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-07-06T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP before 1.5.0 fails to scope message lookups to the current record in ChatterPanel, allowing authenticated users to access arbitrary messages. Attackers can submit sequential message IDs to read, edit, delete, or pin messages from other departments or companies, and enumerate all notes in the system."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-639",
"description": "Authorization Bypass Through User-Controlled Key",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T15:29:10.232Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/aureuserp/aureuserp/commit/d3d5ac20ec544e97636490db6f86a391c04ce899"
},
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1382"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.4.0/plugins/webkul/chatter/src/Livewire/ChatterPanel.php#L503"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.4.0/plugins/webkul/chatter/src/Livewire/ChatterPanel.php#L685"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/idor-chatter-messager-aureus"
},
{
"name": "aureuserp v1.5.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/aureuserp/aureuserp/releases/tag/v1.5.0"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-before-1.5.0-unscoped-message-access-via-chatterpanel"
}
],
"title": "Aureus ERP before 1.5.0 Unscoped Message Access via ChatterPanel",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-95655",
"datePublished": "2026-09-22T15:24:13.836Z",
"dateReserved": "2026-09-22T12:29:08.887Z",
"dateUpdated": "2026-09-28T15:29:10.232Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-94387 (GCVE-0-2026-94387)
Vulnerability from cvelistv5 – Published: 2026-09-21 13:43 – Updated: 2026-09-28 15:29
VLAI
EPSS
VEX
Title
Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log
Summary
Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record's Chatter panel.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 15:17 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
8 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/commit/57c… | patch |
| https://github.com/aureuserp/aureuserp/pull/1465 | patchissue-tracking |
| https://github.com/aureuserp/aureuserp/blob/v1.5.… | technical-description |
| https://github.com/aureuserp/aureuserp/blob/v1.5.… | technical-description |
| https://hackmd.io/@leediay/stored-xss-aureuserp-chatter | third-party-advisory |
| https://github.com/aureuserp/aureuserp/releases/t… | release-notes |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-b… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , < 1.6.0
(semver)
Unaffected: 1.6.0 (semver) |
Date Public
2026-08-05 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-94387",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T15:17:05.399855Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T15:17:23.071Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"vendor": "Webkul",
"versions": [
{
"lessThan": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "1.6.0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-08-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_value and new_value entries are rendered without proper escaping. Any user permitted to edit tracked text fields can inject malicious markup that executes when other users, including administrators, view the record\u0027s Chatter panel."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T15:29:08.702Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/aureuserp/aureuserp/commit/57cf5cf4c98d82a0ad89003402f27823fbe1e27c"
},
{
"name": "PR #1465 chatter-security",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1465"
},
{
"name": "Unescaped old_value render at v1.5.0",
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L165"
},
{
"name": "Unescaped new_value render at v1.5.0",
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.5.0/plugins/webkul/chatter/resources/views/filament/infolists/components/messages/content-text-entry.blade.php#L182"
},
{
"name": "Reporter write-up",
"tags": [
"third-party-advisory"
],
"url": "https://hackmd.io/@leediay/stored-xss-aureuserp-chatter"
},
{
"name": "aureuserp v1.6.0 Release Notes",
"tags": [
"release-notes"
],
"url": "https://github.com/aureuserp/aureuserp/releases/tag/v1.6.0"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-before-1.6.0-stored-xss-via-chatter-field-change-log"
}
],
"title": "Aureus ERP before 1.6.0 Stored XSS via Chatter Field-Change Log",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-94387",
"datePublished": "2026-09-21T13:43:36.234Z",
"dateReserved": "2026-09-21T13:09:30.374Z",
"dateUpdated": "2026-09-28T15:29:08.702Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93988 (GCVE-0-2026-93988)
Vulnerability from cvelistv5 – Published: 2026-09-19 22:58 – Updated: 2026-09-27 14:29
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Arbitrary File Read via getEmailHTML
Summary
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-21 14:13 UTC
CWE
- CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1719 | issue-trackingpatch |
| https://github.com/Qloapps/QloApps/commit/8015495… | patch |
| https://github.com/Qloapps/QloApps/blob/f768898c2… | technical-description |
| https://hackmd.io/@leediay/qloapps-arbitrary-file… | third-party-advisoryexploit |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-05-28 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93988",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-21T14:13:53.418469Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-21T14:14:01.593Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/webkul/qloapps",
"product": "qloapps",
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-05-28T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including database credentials and configuration data."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 7.1,
"baseSeverity": "HIGH",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "NONE"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 6.5,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "LOW",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-22",
"description": "Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-27T14:29:46.872Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "GitHub PR #1719",
"tags": [
"issue-tracking",
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1719"
},
{
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/8015495ca746127920fbcde1f9507c024b26a715"
},
{
"name": "getEmailHTML at v1.7.0",
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/f768898c20c43cb0733a6099e390e5be71631393/controllers/admin/AdminTranslationsController.php#L3038-L3051"
},
{
"tags": [
"third-party-advisory",
"exploit"
],
"url": "https://hackmd.io/@leediay/qloapps-arbitrary-file-read-via-path-traversal"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-arbitrary-file-read-via-getemailhtml"
}
],
"title": "QloApps through 1.7.0 Arbitrary File Read via getEmailHTML",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93988",
"datePublished": "2026-09-19T22:58:09.912Z",
"dateReserved": "2026-09-19T10:55:49.093Z",
"dateUpdated": "2026-09-27T14:29:46.872Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93454 (GCVE-0-2026-93454)
Vulnerability from cvelistv5 – Published: 2026-09-17 23:25 – Updated: 2026-09-22 01:59
VLAI
EPSS
VEX
Title
Aureus ERP through 1.6.0 Stored XSS via Payment Term Note
Summary
Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 01:59 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/aureuserp/aureuserp/pull/1562 | patchissue-tracking |
| https://hackmd.io/@leediay/stored-xss-aureus-via-… | exploit |
| https://github.com/aureuserp/aureuserp/blob/v1.6.… | technical-description |
| https://github.com/aureuserp/aureuserp | product |
| https://www.vulncheck.com/advisories/aureus-erp-t… | third-party-advisory |
Impacted products
1 product
| Vendor | Product | Version | |
|---|---|---|---|
| Webkul | Aureus ERP |
Affected:
0 , ≤ 1.6.0
(semver)
|
Date Public
2026-09-11 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93454",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T01:59:33.777189Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T01:59:49.437Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://packagist.org",
"defaultStatus": "unaffected",
"packageURL": "pkg:composer/aureuserp/aureuserp",
"product": "Aureus ERP",
"repo": "https://github.com/aureuserp/aureuserp",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.6.0",
"status": "affected",
"version": "0",
"versionType": "semver"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-09-11T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plugin. Authenticated users with payment-term create permission can submit arbitrary JavaScript to the payment-terms endpoint, which persists to the database and executes in browsers of all users viewing that Payment Term record."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-17T23:25:13.531Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/aureuserp/aureuserp/pull/1562"
},
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/stored-xss-aureus-via-payment-term"
},
{
"tags": [
"technical-description"
],
"url": "https://github.com/aureuserp/aureuserp/blob/v1.6.0/plugins/webkul/accounts/src/Filament/Resources/PaymentTermResource/Schemas/PaymentTermInfolist.php#L59"
},
{
"tags": [
"product"
],
"url": "https://github.com/aureuserp/aureuserp"
},
{
"name": "VulnCheck Advisory: Aureus ERP through 1.6.0 Stored XSS via Payment Term Note",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/aureus-erp-through-1.6.0-stored-xss-via-payment-term-note"
}
],
"title": "Aureus ERP through 1.6.0 Stored XSS via Payment Term Note",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-93454",
"datePublished": "2026-09-17T23:25:13.531Z",
"dateReserved": "2026-09-17T22:45:31.668Z",
"dateUpdated": "2026-09-22T01:59:49.437Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-92234 (GCVE-0-2026-92234)
Vulnerability from cvelistv5 – Published: 2026-09-15 20:56 – Updated: 2026-09-16 18:02
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors
Summary
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.
Severity
5.4 (Medium)
SSVC
Exploitation: poc
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-16 18:01 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
6 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1796 | patchissue-tracking |
| https://github.com/Qloapps/QloApps/commit/54a3b30… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/mo… | technical-description |
| https://hackmd.io/@leediay/r1aoFrMFGl | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-08-07 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-92234",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-16T18:01:04.208790Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-16T18:02:11.766Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://hackmd.io/@leediay/r1aoFrMFGl"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"programFiles": [
"modules/hotelreservationsystem/controllers/admin/AdminHotelfeaturesController.php"
],
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-08-07T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-15T20:56:46.515Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Fix PR #1796",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/Qloapps/QloApps/pull/1796"
},
{
"name": "Merge commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/54a3b30e4e5c2d6b224dc8fe55e75db173064b91"
},
{
"name": "Unescaped error paths at v1.7.0",
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/modules/hotelreservationsystem/controllers/admin/AdminHotelfeaturesController.php"
},
{
"name": "Reporter write-up",
"tags": [
"technical-description"
],
"url": "https://hackmd.io/@leediay/r1aoFrMFGl"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-hotel-feature-validation-errors"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via Hotel Feature Validation Errors",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-92234",
"datePublished": "2026-09-15T20:56:46.515Z",
"dateReserved": "2026-09-15T19:27:24.634Z",
"dateUpdated": "2026-09-16T18:02:11.766Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-89268 (GCVE-0-2026-89268)
Vulnerability from cvelistv5 – Published: 2026-09-12 01:50 – Updated: 2026-09-14 18:33
VLAI
EPSS
VEX
Title
QloApps through 1.7.0 Reflected XSS via List Filter Parameters
Summary
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Severity
5.4 (Medium)
SSVC
Exploitation: none
Automatable: no
Technical Impact: partial
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-14 18:33 UTC
CWE
- CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Assigner
References
5 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1801 | patchissue-tracking |
| https://github.com/Qloapps/QloApps/commit/153ec1c… | patch |
| https://github.com/Qloapps/QloApps/blob/v1.7.0/ad… | technical-description |
| https://github.com/Qloapps/QloApps | product |
| https://www.vulncheck.com/advisories/qloapps-thro… | third-party-advisory |
Impacted products
Date Public
2026-08-24 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-89268",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-14T18:33:32.753327Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-14T18:33:56.410Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"packageURL": "pkg:github/Qloapps/QloApps",
"product": "QloApps",
"repo": "https://github.com/Qloapps/QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThanOrEqual": "1.7.0",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*",
"versionEndIncluding": "1.7.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "leediay153"
}
],
"datePublic": "2026-08-24T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim\u0027s session to read administrative data and perform actions."
}
],
"metrics": [
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"privilegesRequired": "LOW",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "LOW",
"subIntegrityImpact": "LOW",
"userInteraction": "PASSIVE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"vulnIntegrityImpact": "LOW"
},
"format": "CVSS"
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.4,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"privilegesRequired": "LOW",
"scope": "CHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"version": "3.1"
},
"format": "CVSS"
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-79",
"description": "Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-12T01:50:33.852Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request #1801",
"tags": [
"patch",
"issue-tracking"
],
"url": "https://github.com/Qloapps/QloApps/pull/1801"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/commit/153ec1c8567798bd99155098ecc0a340e38f25bf"
},
{
"name": "Unescaped filter values in list_header.tpl at v1.7.0",
"tags": [
"technical-description"
],
"url": "https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/helpers/list/list_header.tpl"
},
{
"tags": [
"product"
],
"url": "https://github.com/Qloapps/QloApps"
},
{
"name": "VulnCheck Advisory: QloApps through 1.7.0 Reflected XSS via List Filter Parameters",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-list-filter-parameters"
}
],
"title": "QloApps through 1.7.0 Reflected XSS via List Filter Parameters",
"x_generator": {
"engine": "vulncheck-endgame"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-89268",
"datePublished": "2026-09-12T01:50:33.852Z",
"dateReserved": "2026-09-11T10:52:56.669Z",
"dateUpdated": "2026-09-14T18:33:56.410Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75498 (GCVE-0-2026-75498)
Vulnerability from cvelistv5 – Published: 2026-08-25 16:37 – Updated: 2026-08-25 18:06
VLAI
EPSS
VEX
Title
Webkul QloApps SQL injection
Summary
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-18 14:33 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
References
3 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1783/chan… | patch |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-75498 | vdb-entry |
Impacted products
Date Public
2026-08-13 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75498",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:06:10.525444Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:06:22.590Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThan": "123c97c",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "123c97c"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "leediay153"
}
],
"datePublic": "2026-08-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the \u0027bo_query\u0027 parameter in the \u0027Address.php\u0027 file. Fixed in 123c97c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-75498",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T14:33:09.059645Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T16:37:43.725Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-75498"
}
],
"title": "Webkul QloApps SQL injection"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-75498",
"datePublished": "2026-08-25T16:37:43.725Z",
"dateReserved": "2026-08-17T20:16:01.457Z",
"dateUpdated": "2026-08-25T18:06:22.590Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75497 (GCVE-0-2026-75497)
Vulnerability from cvelistv5 – Published: 2026-08-25 16:37 – Updated: 2026-08-25 18:05
VLAI
EPSS
VEX
Title
Webkul QloApps SQL injection
Summary
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-18 14:32 UTC
CWE
- CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
References
3 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1783/chan… | patch |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-75497 | vdb-entry |
Impacted products
Date Public
2026-08-13 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75497",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:05:50.184882Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:05:58.384Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThan": "123c97c",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "123c97c"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "leediay153"
}
],
"datePublic": "2026-08-13T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the \u0027bo_query\u0027 parameter in the \u0027CustomerMessage.php\u0027 file. Fixed in 123c97c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-75497",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-18T14:32:30.238898Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-89",
"description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T16:37:10.271Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1783/changes/123c97c110b7053ea3297d8e58fe95b3c3536560"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-75497"
}
],
"title": "Webkul QloApps SQL injection"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-75497",
"datePublished": "2026-08-25T16:37:10.271Z",
"dateReserved": "2026-08-17T20:16:01.457Z",
"dateUpdated": "2026-08-25T18:05:58.384Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-75496 (GCVE-0-2026-75496)
Vulnerability from cvelistv5 – Published: 2026-08-25 16:36 – Updated: 2026-08-25 18:05
VLAI
EPSS
VEX
Title
Webkul QloApps improper file upload validation
Summary
Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c.
Severity
SSVC
Exploitation: poc
Automatable: no
Technical Impact: total
CISA Coordinator · cisa-cg (v2.0.3)
Decision recorded 2026-08-17 20:27 UTC
CWE
- CWE-434 - Unrestricted Upload of File with Dangerous Type
References
3 references
| URL | Tags |
|---|---|
| https://github.com/Qloapps/QloApps/pull/1801/comm… | patch |
| https://raw.githubusercontent.com/cisagov/CSAF/de… | third-party-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-75496 | vdb-entry |
Impacted products
Date Public
2026-07-20 00:00
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-75496",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-25T18:05:24.426739Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T18:05:38.099Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "QloApps",
"vendor": "Webkul",
"versions": [
{
"lessThan": "153ec1c",
"status": "affected",
"version": "0",
"versionType": "custom"
},
{
"status": "unaffected",
"version": "153ec1c"
}
]
}
],
"credits": [
{
"lang": "en",
"value": "leediay153"
}
],
"datePublic": "2026-07-20T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 7.2,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "HIGH",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"cvssV4_0": {
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 8.6,
"baseSeverity": "HIGH",
"privilegesRequired": "HIGH",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH"
}
},
{
"other": {
"content": {
"id": "CVE-2026-75496",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-17T20:27:36.847949Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-25T16:36:42.577Z",
"orgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"shortName": "cisa-cg"
},
"references": [
{
"name": "url",
"tags": [
"patch"
],
"url": "https://github.com/Qloapps/QloApps/pull/1801/commits/153ec1c8567798bd99155098ecc0a340e38f25bf"
},
{
"name": "url",
"tags": [
"third-party-advisory"
],
"url": "https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-237-01.json"
},
{
"name": "url",
"tags": [
"vdb-entry"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-75496"
}
],
"title": "Webkul QloApps improper file upload validation"
}
},
"cveMetadata": {
"assignerOrgId": "9119a7d8-5eab-497f-8521-727c672e3725",
"assignerShortName": "cisa-cg",
"cveId": "CVE-2026-75496",
"datePublished": "2026-08-25T16:36:42.577Z",
"dateReserved": "2026-08-17T20:16:01.457Z",
"dateUpdated": "2026-08-25T18:05:38.099Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}