CVE-2026-101139
- EPSS 0.29%
- Veröffentlicht 28.09.2026 19:16:47
- Zuletzt bearbeitet 29.09.2026 17:17:05
A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing aut...
CVE-2026-79411
- EPSS 0.15%
- Veröffentlicht 15.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admi...
CVE-2026-79410
- EPSS 0.35%
- Veröffentlicht 15.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.
CVE-2026-79409
- EPSS 0.42%
- Veröffentlicht 15.09.2026 00:00:00
- Zuletzt bearbeitet 22.09.2026 20:00:03
An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.
- EPSS 0.33%
- Veröffentlicht 18.08.2026 00:00:12
- Zuletzt bearbeitet 20.08.2026 12:48:10
A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes b...
CVE-2026-75081
- EPSS 0.27%
- Veröffentlicht 17.08.2026 23:45:08
- Zuletzt bearbeitet 20.08.2026 12:48:10
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow....
CVE-2026-19997
- EPSS 0.39%
- Veröffentlicht 17.08.2026 07:00:09
- Zuletzt bearbeitet 20.08.2026 12:48:10
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass...
CVE-2026-19996
- EPSS 0.34%
- Veröffentlicht 17.08.2026 06:45:07
- Zuletzt bearbeitet 20.08.2026 12:48:10
A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privil...
- EPSS 0.19%
- Veröffentlicht 17.08.2026 06:30:08
- Zuletzt bearbeitet 20.08.2026 12:48:10
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Rem...
CVE-2026-19993
- EPSS 0.27%
- Veröffentlicht 17.08.2026 06:17:39
- Zuletzt bearbeitet 20.08.2026 12:48:10
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of b...