Webkul

Bagisto

39 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.29%
  • Veröffentlicht 17.08.2026 06:15:08
  • Zuletzt bearbeitet 20.08.2026 12:48:31

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.08.2026 16:00:06
  • Zuletzt bearbeitet 14.08.2026 19:09:39

A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote ...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 14.08.2026 15:45:06
  • Zuletzt bearbeitet 14.08.2026 19:09:39

A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The at...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 14.08.2026 15:30:07
  • Zuletzt bearbeitet 18.08.2026 14:16:58

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID r...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 14.08.2026 15:15:07
  • Zuletzt bearbeitet 14.08.2026 19:09:39

A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 14.08.2026 15:00:08
  • Zuletzt bearbeitet 18.08.2026 02:17:26

A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authoriza...

  • EPSS 0.2%
  • Veröffentlicht 09.07.2026 20:43:07
  • Zuletzt bearbeitet 14.07.2026 23:17:35

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malici...

  • EPSS 1.24%
  • Veröffentlicht 08.06.2026 09:28:51
  • Zuletzt bearbeitet 23.07.2026 07:10:00

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the ...

  • EPSS 1.28%
  • Veröffentlicht 02.01.2026 20:38:48
  • Zuletzt bearbeitet 08.01.2026 21:20:38

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 02.01.2026 20:37:06
  • Zuletzt bearbeitet 08.01.2026 21:20:06

Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the fil...