CVE-2026-19835
- EPSS 0.26%
- Veröffentlicht 14.08.2026 15:15:07
- Zuletzt bearbeitet 14.08.2026 19:09:39
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched...
CVE-2026-19834
- EPSS 0.31%
- Veröffentlicht 14.08.2026 15:00:08
- Zuletzt bearbeitet 18.08.2026 02:17:26
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authoriza...
CVE-2026-60120
- EPSS 0.2%
- Veröffentlicht 09.07.2026 20:43:07
- Zuletzt bearbeitet 14.07.2026 23:17:35
Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malici...
CVE-2026-9506
- EPSS 1.24%
- Veröffentlicht 08.06.2026 09:28:51
- Zuletzt bearbeitet 23.07.2026 07:10:00
This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the ...
CVE-2026-21450
- EPSS 1.28%
- Veröffentlicht 02.01.2026 20:38:48
- Zuletzt bearbeitet 08.01.2026 21:20:38
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.
CVE-2026-21451
- EPSS 0.51%
- Veröffentlicht 02.01.2026 20:37:06
- Zuletzt bearbeitet 08.01.2026 21:20:06
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the fil...
CVE-2026-21449
- EPSS 0.47%
- Veröffentlicht 02.01.2026 20:35:21
- Zuletzt bearbeitet 08.01.2026 21:21:59
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue.
CVE-2026-21448
- EPSS 0.85%
- Veröffentlicht 02.01.2026 20:18:08
- Zuletzt bearbeitet 08.01.2026 21:22:34
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a value to run in admin view. The is...
CVE-2026-21447
- EPSS 0.29%
- Veröffentlicht 02.01.2026 20:15:11
- Zuletzt bearbeitet 08.01.2026 21:24:08
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to th...
CVE-2026-21446
- EPSS 0.59%
- Veröffentlicht 02.01.2026 19:18:36
- Zuletzt bearbeitet 08.01.2026 21:25:06
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exp...