Webkul · Qloapps · CVE-2026-75496
**Name of the Vulnerable Software and Affected Versions**
Webkul QloApps (affected versions not specified)
**Description**
Improper validation of uploaded file extensions or MIME types allows a remote, authenticated attacker with administrative privileges to upload executable files to a publicly accessible directory, leading to remote code execution.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.