VendorsWebkulbagisto1.5.1
Vulnerabilities

Webkul Bagisto 1.5.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2023-33570
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
Published 2023-06-28 · Modified
8.8EPSS 0.011
CVE-2023-36238
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
Published 2024-03-13 · Analyzed
6.5EPSS 0.005
CVE-2024-27499
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
Published 2024-03-01 · Modified
6.5EPSS 0.005