Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/qloapps

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

QloApps versions up to and including 1.7.0 have a path traversal vulnerability in the getEmailHTML action of admin/ajax.php. This flaw allows authenticated back-office users to read arbitrary files by supplying relative path sequences in the email parameter, potentially exposing sensitive files such as database credentials and configuration data.

Join the discussion

QloApps through 1.7.0 reflects unescaped child feature names into back-office validation error messages in the Hotel Reservation System feature management page. Authenticated back-office users who follow a crafted link can execute injected JavaScript in their administrative session via the child_features parameter.

Join the discussion

QloApps versions up to 1.7.0 have a cross-site scripting (XSS) vulnerability in the back-office list filter functionality. This occurs because POST parameters are rendered into HTML input value attributes without proper escaping. Authenticated attackers can craft POST requests that execute arbitrary JavaScript in the context of an administrator's session, potentially exposing administrative data and enabling unauthorized actions.

Join the discussion
CVE-2025-67325: n/aCVE-2025-67325
0

Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote code execution.

Join the discussion
0

A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /admin/ajax_products_list.php. The manipulation of the argument packItself leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor confirms the existence of this flaw but considers it a low-level issue due to admin privilege pre-requisites. Still, a fix is planned for a future release.

Join the discussion
CVE-2024-40318: n/aCVE-2024-40318
0

An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/qloapps
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses