Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in restriction_min_los and restriction_max_los parameters, executing… | |
| Aplazada | Media (5.1) | 0.19% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users to submit crafted POST requests with malicious payloads to execute… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 30/9/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that executes in an authenticated administrator's session when the victim… | |
| Aplazada | Media (5.1) | 0.18% | — | Webkul QloappsAI | 30/9/2026 | 1/10/2026 | QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can craft a malicious link containing JavaScript payload in these… | |
| Aplazada | Alta (7.1) | 0.55% | — | Qloapps QloapsAI | 19/9/2026 | 22/9/2026 | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to bypass directory restrictions and access sensitive files including… | |
| Pendiente de análisis | Alta (8.6) | 0.81% | — | Webkul QloappsAI | 25/8/2026 | 26/8/2026 | Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97c. | |
| Pendiente de análisis | Alta (8.6) | 0.98% | — | Webkul QloappsAI | 25/8/2026 | 26/8/2026 | Webkul QloApps does not perform proper validation on uploaded file extensions or MIME types before moving the file to a publicly accessible directory. A remote, authenticated attacker with administrative privileges could upload executable files and achieve remote code execution. Fixed in 153ec1c. | |
| Aplazada | Media (4.8) | 0.30% | — | Webkul QloappsAI | 8/6/2026 | 23/7/2026 | QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to… | |
| Aplazada | Alta (8.2) | 0.27% | — | Webkul QloappsAI | 2/6/2026 | 22/7/2026 | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the… | |
| Analizada | Media (5.4) | 0.14% | — | Webkul Qloapps | 12/1/2026 | 17/6/2026 | A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document. | |
| Analizada | Crítica (9.8) | 0.92% | — | Webkul Qloapps | 8/1/2026 | 17/6/2026 | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution. | |
| Analizada | Media (5.5) | 0.35% | — | Webkul Qloapps | 21/9/2025 | 17/6/2026 | A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipulation of the argument token results in authorization bypass. The attack may be initiated remotely. The exploit is now public and may be used. The vendor explains: "As We… | |
| Analizada | Baja (2) | 0.57% | — | Webkul Qloapps | 17/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the… | |
| Analizada | Media (4.2) | 0.22% | — | Webkul Qloapps | 18/2/2025 | 17/6/2026 | Webkul QloApps v1.6.1 exposes authentication tokens in URLs during redirection. When users access the admin panel or other protected areas, the application appends sensitive authentication tokens directly to the URL. | |
| Analizada | Media (5.3) | 0.54% | — | Webkul Qloapps | 10/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the component Your Location Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. It is planned to remove this page in the long… | |
| Analizada | Media (5.3) | 0.33% | — | Webkul Qloapps | 6/2/2025 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. Affected is the function logout of the file /en/?mylogout of the component URL Handler. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the… | |
| Modificada | Alta (7.2) | 1.2% | — | Webkul Qloapps | 25/7/2024 | 17/6/2026 | An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file. | |
| Modificada | Media (6.5) | 0.66% | — | Webkul Qloapps | 17/1/2024 | 17/6/2026 | An issue in webkul qloapps before v1.6.0 allows an attacker to obtain sensitive information via the id_order parameter. | |
| Modificada | Media (6.1) | 1.2% | — | Webkul Qloapps | 23/6/2023 | 17/6/2026 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST controller parameter. | |
| Modificada | Alta (7.5) | 3.2% | — | Webkul Qloapps | 23/6/2023 | 17/6/2026 | An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database. | |
| Modificada | Media (6.1) | 1.2% | — | Webkul Qloapps | 23/6/2023 | 17/6/2026 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via POST email_create and back parameter. | |
| Modificada | Media (5.4) | 0.44% | — | Webkul Qloapps | 23/6/2023 | 17/6/2026 | An unauthenticated Cross-Site Scripting (XSS) vulnerability found in Webkul QloApps 1.6.0 allows an attacker to obtain a user's session cookie and then impersonate that user via GET configure parameter. | |
| Modificada | Media (6.1) | 9.1% | — | Webkul Qloapps | 11/5/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Webkil QloApps v.1.5.2 allows a remote attacker to obtain sensitive information via the back and email_create parameters in the AuthController.php file. |