VendorsWebkulbagistoany version
Vulnerabilities

Webkul Bagisto any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-21450
Bagisto has SSTI in parameter that can lead to RCE
Published 2026-01-02 · Analyzed
9.8EPSS 0.014
CVE-2026-21448
Bagisto has Normal & Blind SSTI from low-privilege user when ordering product
Published 2026-01-02 · Analyzed
9.8EPSS 0.009
CVE-2026-21446
Bagisto Missing Authentication on Installer API Endpoints
Published 2026-01-02 · Analyzed
9.8EPSS 0.006
CVE-2019-16403
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
Published 2019-09-18 · Modified
8.8EPSS 0.014
CVE-2026-21449
Bagisto has SSTI via first and last name from low-privilege user (not admin)
Published 2026-01-02 · Analyzed
8.8EPSS 0.005
CVE-2023-36237
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
Published 2024-02-26 · Analyzed
8.8EPSS 0.004
CVE-2026-21451
Bagisto has HTML Filter Bypass that Enables Stored XSS
Published 2026-01-02 · Analyzed
8.4EPSS 0.006
CVE-2026-21447
Bagisto has IDOR in Customer Order Reorder Functionality
Published 2026-01-02 · Analyzed
7.1EPSS 0.003
CVE-2025-40675
Reflected Cross-Site Scripting (XSS) in Bagisto
Published 2025-06-09 · Analyzed
6.1EPSS 0.002
CVE-2023-36236
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
Published 2024-01-16 · Modified
4.8EPSS 0.006