CVE-2026-21450
- EPSS 0.69%
- Veröffentlicht 02.01.2026 20:38:48
- Zuletzt bearbeitet 08.01.2026 21:20:38
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.
CVE-2026-21451
- EPSS 0.03%
- Veröffentlicht 02.01.2026 20:37:06
- Zuletzt bearbeitet 08.01.2026 21:20:06
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the fil...
CVE-2026-21449
- EPSS 0.02%
- Veröffentlicht 02.01.2026 20:35:21
- Zuletzt bearbeitet 08.01.2026 21:21:59
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.
CVE-2026-21448
- EPSS 0.15%
- Veröffentlicht 02.01.2026 20:18:08
- Zuletzt bearbeitet 08.01.2026 21:22:34
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The is...
CVE-2026-21447
- EPSS 0.01%
- Veröffentlicht 02.01.2026 20:15:11
- Zuletzt bearbeitet 08.01.2026 21:24:08
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to th...
CVE-2026-21446
- EPSS 0.13%
- Veröffentlicht 02.01.2026 19:18:36
- Zuletzt bearbeitet 08.01.2026 21:25:06
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exp...
CVE-2025-62415
- EPSS 0.07%
- Veröffentlicht 16.10.2025 18:36:51
- Zuletzt bearbeitet 22.10.2025 17:21:31
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing embedded JavaScript. When viewed, the ...
CVE-2025-62418
- EPSS 0.07%
- Veröffentlicht 16.10.2025 18:35:06
- Zuletzt bearbeitet 22.10.2025 16:55:04
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the m...
CVE-2025-62414
- EPSS 0.07%
- Veröffentlicht 16.10.2025 18:33:03
- Zuletzt bearbeitet 22.10.2025 17:21:50
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An attacker with access to the admin create-customer form can inject maliciou...
CVE-2025-62416
- EPSS 0.28%
- Veröffentlicht 16.10.2025 18:32:55
- Zuletzt bearbeitet 22.10.2025 17:06:55
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This a...