CVE-2026-105836
- EPSS 0.23%
- Veröffentlicht 06.10.2026 12:57:55
- Zuletzt bearbeitet 06.10.2026 13:16:47
QloApps through 1.7.0 contains an authorization bypass vulnerability in AdminProductsController::ajaxProcessBulkUpdateRooms that allows hotel-restricted back-office employees to modify rooms of other hotels. Attackers can submit foreign room IDs in t...
CVE-2026-103590
- EPSS 0.19%
- Veröffentlicht 30.09.2026 23:16:58
- Zuletzt bearbeitet 01.10.2026 15:17:28
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor's length of stay fields. Attackers can induce authenticated administrators to submit crafted POST requests with malicious payloads in re...
CVE-2026-103589
- EPSS 0.19%
- Veröffentlicht 30.09.2026 23:16:58
- Zuletzt bearbeitet 01.10.2026 19:17:18
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office room type editor that fails to escape room_num, floor, and comment field values in input attributes. Attackers can induce authenticated back-office users...
CVE-2026-103588
- EPSS 0.18%
- Veröffentlicht 30.09.2026 23:16:58
- Zuletzt bearbeitet 06.10.2026 00:16:32
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the exceptions field of the back-office Transplant a module form. Attackers can craft a malicious link containing JavaScript payload in the exceptions parameter that exe...
CVE-2026-103587
- EPSS 0.18%
- Veröffentlicht 30.09.2026 23:16:58
- Zuletzt bearbeitet 01.10.2026 16:17:37
QloApps through 1.7.0 contains a reflected cross-site scripting vulnerability in the back-office Hotel Reservation System Book Now search, where date_to and id_room_type parameters are copied into template variables without validation. Attackers can ...
CVE-2026-93988
- EPSS 0.37%
- Veröffentlicht 19.09.2026 22:58:09
- Zuletzt bearbeitet 22.09.2026 20:43:58
QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows authenticated back-office users to read arbitrary files. Attackers can supply relative path sequences in the email parameter to byp...
CVE-2026-92234
- EPSS 0.19%
- Veröffentlicht 15.09.2026 20:56:46
- Zuletzt bearbeitet 16.09.2026 20:21:01
QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript...
CVE-2026-89268
- EPSS 0.17%
- Veröffentlicht 12.09.2026 01:50:33
- Zuletzt bearbeitet 23.09.2026 17:17:47
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads...
CVE-2026-75498
- EPSS 0.44%
- Veröffentlicht 25.08.2026 16:37:43
- Zuletzt bearbeitet 26.08.2026 16:52:20
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'Address.php' file. Fixed in 123c97c.
CVE-2026-75497
- EPSS 0.44%
- Veröffentlicht 25.08.2026 16:37:10
- Zuletzt bearbeitet 26.08.2026 16:52:20
Webkul QloApps does not validate request parameters before a database query. A remote, authenticated attacker with administrative privileges could send a crafted SQL query to the 'bo_query' parameter in the 'CustomerMessage.php' file. Fixed in 123c97...