VendorsWebkulbagistoall versions
Vulnerabilities

Webkul Bagisto

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

21CVEs
CVE-2026-21450
Bagisto has SSTI in parameter that can lead to RCE
Published 2026-01-02 · Analyzed
9.8EPSS 0.014
CVE-2026-21448
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
Published 2026-01-02 · Analyzed
9.8EPSS 0.009
CVE-2026-21446
Bagisto Missing Authentication on Installer API Endpoints
Published 2026-01-02 · Analyzed
9.8EPSS 0.006
CVE-2019-16403
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
Published 2019-09-18 · Modified
8.8EPSS 0.014
CVE-2023-33570
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
Published 2023-06-28 · Modified
8.8EPSS 0.011
CVE-2019-14933
Bagisto 0.1.5 allows CSRF under /admin URIs.
Published 2019-08-11 · Modified
8.8EPSS 0.006
CVE-2026-21449
Bagisto has SSTI via first and last name from low-privilege user (not admin)
Published 2026-01-02 · Analyzed
8.8EPSS 0.005
CVE-2023-36237
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
Published 2024-02-26 · Analyzed
8.8EPSS 0.004
CVE-2026-21451
Bagisto has HTML Filter Bypass that Enables Stored XSS
Published 2026-01-02 · Analyzed
8.4EPSS 0.006
CVE-2025-60880
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.
Published 2025-10-10 · Analyzed
8.3EPSS 0.004
CVE-2025-62417
bagisto - CSV Formula Injection in Create New Product
Published 2025-10-16 · Analyzed
7.8EPSS 0.004
CVE-2026-21447
Bagisto has IDOR in Customer Order Reorder Functionality
Published 2026-01-02 · Analyzed
7.1EPSS 0.003
CVE-2025-62414
bagisto - Cross Site Scripting (XSS) in Create New Customer
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-62418
bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (SVG)
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-62415
bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (HTML)
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-62416
bagisto - Server Side Template Injection (SSTI) in Product Description
Published 2025-10-16 · Analyzed
6.8EPSS 0.004
CVE-2023-36238
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
Published 2024-03-13 · Analyzed
6.5EPSS 0.005
CVE-2024-27499
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
Published 2024-03-01 · Modified
6.5EPSS 0.005
CVE-2025-56426
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.
Published 2025-10-09 · Analyzed
6.5EPSS 0.004
CVE-2025-40675
Reflected Cross-Site Scripting (XSS) in Bagisto
Published 2025-06-09 · Analyzed
6.1EPSS 0.002
CVE-2023-36236
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
Published 2024-01-16 · Modified
4.8EPSS 0.006