Webkul

Bagisto

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 28.09.2026 19:16:47
  • Zuletzt bearbeitet 29.09.2026 17:17:05

A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing aut...

  • EPSS 0.15%
  • Veröffentlicht 15.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 20:00:03

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admi...

  • EPSS 0.35%
  • Veröffentlicht 15.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 20:00:03

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

  • EPSS 0.42%
  • Veröffentlicht 15.09.2026 00:00:00
  • Zuletzt bearbeitet 22.09.2026 20:00:03

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 18.08.2026 00:00:12
  • Zuletzt bearbeitet 20.08.2026 12:48:10

A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes b...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 17.08.2026 23:45:08
  • Zuletzt bearbeitet 20.08.2026 12:48:10

A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow....

Exploit
  • EPSS 0.39%
  • Veröffentlicht 17.08.2026 07:00:09
  • Zuletzt bearbeitet 20.08.2026 12:48:10

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass...

Exploit
  • EPSS 0.34%
  • Veröffentlicht 17.08.2026 06:45:07
  • Zuletzt bearbeitet 20.08.2026 12:48:10

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privil...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 17.08.2026 06:30:08
  • Zuletzt bearbeitet 20.08.2026 12:48:10

A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Rem...

  • EPSS 0.27%
  • Veröffentlicht 17.08.2026 06:17:39
  • Zuletzt bearbeitet 20.08.2026 12:48:10

A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of b...