📦 Bagisto

by Webkul

🔍 What is Bagisto?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21450

CRITICAL CVSS 9.8 Jan 2, 2026

Bagisto eCommerce platforms running versions before 2.3.10 are vulnerable to server-side template injection via the type parameter. This allows attackers to execute arbitrary code remotely, potentiall...

CVE-2026-21448

CRITICAL CVSS 9.8 Jan 2, 2026

Bagisto eCommerce platform versions before 2.3.10 are vulnerable to server-side template injection that can lead to remote code execution. When customers add addresses during checkout, they can inject...

CVE-2026-21446

CRITICAL CVSS 9.8 Jan 2, 2026

Bagisto eCommerce platform versions before 2.3.10 have unprotected API endpoints that remain accessible after installation. Unauthenticated attackers can directly access these endpoints to create admi...

CVE-2026-21449

HIGH CVSS 8.8 Jan 2, 2026

Bagisto eCommerce platform versions before 2.3.10 are vulnerable to server-side template injection (SSTI) through first name and last name fields. This allows low-privilege users to execute arbitrary ...

CVE-2026-21451

HIGH CVSS 8.4 Jan 2, 2026

A stored Cross-Site Scripting (XSS) vulnerability in Bagisto eCommerce platform allows attackers to inject malicious JavaScript into CMS pages by bypassing input sanitization via HTTP POST manipulatio...

CVE-2026-21447

HIGH CVSS 7.1 Jan 2, 2026

An Insecure Direct Object Reference vulnerability in Bagisto eCommerce platform allows authenticated customers to add items from other customers' orders to their own cart by manipulating order IDs. Th...

CVE-2025-62417

HIGH CVSS 7.8 Oct 16, 2025

Bagisto eCommerce platform versions before 2.3.8 accept product data starting with spreadsheet formula characters (=, +, -, @). When exported to CSV and opened in spreadsheet software, these cells are...

CVE-2025-60880

HIGH CVSS 8.3 Oct 10, 2025

An authenticated stored XSS vulnerability in Bagisto 2.3.6 allows admin users to upload malicious SVG files containing JavaScript code. When viewed, this code executes in victims' browsers, potentiall...

CVE-2023-36237

HIGH CVSS 8.8 Feb 26, 2024

This Cross-Site Request Forgery (CSRF) vulnerability in Bagisto e-commerce platform allows attackers to trick authenticated users into executing malicious actions without their consent. Attackers can ...

CVE-2023-33570

HIGH CVSS 8.8 Jun 28, 2023

Bagisto v1.5.1 contains a Server-Side Template Injection (SSTI) vulnerability that allows attackers to execute arbitrary code on the server. This affects all Bagisto installations running version 1.5....

CVE-2025-62415

MEDIUM CVSS 6.9 Oct 16, 2025

This vulnerability allows authenticated administrators in Bagisto v2.3.7 to upload malicious HTML files containing JavaScript through the TinyMCE image upload feature. When these files are viewed, the...

CVE-2025-62416

MEDIUM CVSS 5.1 Oct 16, 2025

Bagisto v2.3.7 has a Server-Side Template Injection vulnerability in product description rendering that allows authenticated attackers with product creation privileges to execute arbitrary code on the...

CVE-2025-56426

MEDIUM CVSS 6.5 Oct 9, 2025

A remote code execution vulnerability in WebKul Bagisto v2.3.6 allows attackers to execute arbitrary code via the Cart/Checkout API endpoint. The price calculation logic fails to properly validate qua...

CVE-2025-40675

MEDIUM CVSS 6.1 Jun 9, 2025

A reflected XSS vulnerability in Bagisto v2.0.0 allows attackers to execute malicious JavaScript in victims' browsers via crafted URLs containing malicious 'query' parameters in the search endpoint. T...