Unopim Webkul Unopim

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Webkul Unopim.

By the Year

In 2026 there have been 1 vulnerability in Webkul Unopim with an average score of 7.1 out of ten. Unopim did not have any published security vulnerabilities last year. That is, 1 more vulnerability have already been reported in 2026 as compared to last year.

Year Vulnerabilities Average Score
2026 1 7.10
2025 0 0.00
2024 2 4.80

It may take a day or so for new Unopim vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Webkul Unopim Security Vulnerabilities

UnoPim <2.1.3: ACL Bypass Enables Unlimited OAuth & Permission Escalation
CVE-2026-85395 7.1 - High - September 03, 2026

UnoPim before 2.1.3 fails to include integration store, update, and key-generation routes in its ACL map, allowing any admin user to bypass permission checks. Attackers with minimal admin privileges can create OAuth API integrations, mint client credentials, and escalate permissions by exploiting missing authorization validation in the Bouncer middleware.

AuthZ

UnoPim Laravel Framework SVG File Upload Session Hijacking Vulnerability
CVE-2024-52305 4.8 - Medium - November 13, 2024

UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. A vulnerability exists in the Create User process, allowing the creation of a new admin account with an option to upload a profile image. An attacker can upload a malicious SVG file containing an embedded script. When the profile image is accessed, the embedded script executes, leading to the potential theft of session cookies. This vulnerability is fixed in 0.1.5.

PHP

UnoPim 0.1.3 XSS via SVG in Create User
CVE-2024-50637 - November 06, 2024

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Webkul Unopim or by Webkul? Click the Watch button to subscribe.

Webkul
Vendor

Webkul Unopim
Product

subscribe