CVE-2025-62417
- EPSS 0.22%
- Veröffentlicht 16.10.2025 18:32:45
- Zuletzt bearbeitet 22.10.2025 17:00:09
Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadshee...
CVE-2025-60880
- EPSS 0.03%
- Veröffentlicht 10.10.2025 00:00:00
- Zuletzt bearbeitet 08.01.2026 21:27:07
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated...
CVE-2025-56426
- EPSS 0.17%
- Veröffentlicht 09.10.2025 00:00:00
- Zuletzt bearbeitet 30.10.2025 14:30:40
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.
CVE-2025-40675
- EPSS 0.04%
- Veröffentlicht 09.06.2025 09:42:18
- Zuletzt bearbeitet 06.10.2025 19:55:19
A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/sea...
CVE-2023-36238
- EPSS 0.15%
- Veröffentlicht 13.03.2024 21:15:53
- Zuletzt bearbeitet 14.04.2025 13:13:25
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
CVE-2024-27499
- EPSS 0.05%
- Veröffentlicht 01.03.2024 16:15:46
- Zuletzt bearbeitet 11.08.2025 16:15:29
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
CVE-2023-36237
- EPSS 0.18%
- Veröffentlicht 26.02.2024 22:15:06
- Zuletzt bearbeitet 11.04.2025 20:20:35
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
CVE-2023-36236
- EPSS 0.23%
- Veröffentlicht 16.01.2024 22:15:37
- Zuletzt bearbeitet 17.06.2025 15:15:35
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
CVE-2023-33570
- EPSS 0.37%
- Veröffentlicht 28.06.2023 20:15:09
- Zuletzt bearbeitet 27.11.2024 17:15:06
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
CVE-2019-16403
- EPSS 0.28%
- Veröffentlicht 18.09.2019 12:15:11
- Zuletzt bearbeitet 21.11.2024 04:30:38
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.