Skip to main content

Vendor/product archive

webkul / bagisto CVEs

Beta · best-effort

21 CVEs tagged to webkul / bagisto0 Critical, 11 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2026-21451

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Altho…

CVSS 5.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21450

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code e…

CVSS 7.3 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21449

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege u…

CVSS 7.4 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21448

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-21447

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any…

CVSS 7.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-21446

Published Jan 2, 2026

Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The unde…

CVSS 8.8 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2025-62418

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to uploa…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62417

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-62416

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the se…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62415

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to uploa…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62414

Published Oct 16, 2025

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An att…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60880

Published Oct 10, 2025

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious J…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-56426

Published Oct 9, 2025

An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-40675

Published Jun 9, 2025

A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36238

Published Mar 13, 2024

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27499

Published Mar 1, 2024

Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-36237

Published Feb 26, 2024

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36236

Published Jan 16, 2024

Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33570

Published Jun 28, 2023

Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16403

Published Sep 18, 2019

In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1