Webkul Unopim
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Webkul Unopim.
By the Year
In 2026 there have been 1 vulnerability in Webkul Unopim with an average score of 7.1 out of ten. Unopim did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 1 | 7.10 |
| 2025 | 0 | 0.00 |
| 2024 | 2 | 4.80 |
It may take a day or so for new Unopim vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Webkul Unopim Security Vulnerabilities
UnoPim <2.1.3: ACL Bypass Enables Unlimited OAuth & Permission Escalation
CVE-2026-85395
7.1 - High
- September 03, 2026
UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.
AuthZ
UnoPim Laravel Framework SVG File Upload Session Hijacking Vulnerability
CVE-2024-52305
4.8 - Medium
- November 13, 2024
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.
PHP
UnoPim 0.1.3 XSS via SVG in Create User
CVE-2024-50637
- November 06, 2024
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Webkul Unopim or by Webkul? Click the Watch button to subscribe.