CVE-2024-50637: Webkul Unopim

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG document, which can be used to steal cookies.

Affected products

  • Webkul Unopim: before 0.1.4 (fixed in 0.1.4)

Published 2024-11-06. Last modified 2026-06-17.