CVE Feed

    Dashboard / CVE / CVE-2026-25861

    CVE-2026-25861

    QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password hashing in the Tools::encrypt() function within classes/Tools.php, which concatenates a static cookie key with the supplied password. Attackers can perform offline brute-force attacks against the MD5 hashes, with the risk compounded by auto-generated 8-character passwords assigned during guest-to-customer account conversion in classes/Customer.php, making credential recovery trivial.

    Published:Jun 2, 2026
    Last Modified:Jul 14, 2026
    EPS:Jun 2, 2026
    EPSS Score:0.00178
    CVSS Score:5.9

    Affected Products

    Vendor
    Qloapps
    Product
    Qloapps
    Vendor
    Webkul
    Product
    Qloapps

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High