CVE-2024-0916: Webkul Uvdesk

Critical severity, CVSS 10.0. EPSS: 1% chance of exploitation in the next 30 days.

Unauthenticated file upload allows remote code execution. This issue affects UvDesk Community: from 1.0.0 through 1.1.3.

Affected products

  • Webkul Uvdesk: from 1.0.0, up to and including 1.1.3
  • Webkul Software Uvdesk Community: from 1.0.0, up to and including 1.1.3

Published 2024-04-25. Last modified 2026-06-17.