VendorsWebkulbagisto2.3.7
Vulnerabilities

Webkul Bagisto 2.3.7

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2025-62417
bagisto - CSV Formula Injection in Create New Product
Published 2025-10-16 · Analyzed
7.8EPSS 0.004
CVE-2025-62414
bagisto - Cross Site Scripting (XSS) in Create New Customer
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-62415
bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (HTML)
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-62418
bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (SVG)
Published 2025-10-16 · Analyzed
6.9EPSS 0.003
CVE-2025-62416
bagisto - Server Side Template Injection (SSTI) in Product Description
Published 2025-10-16 · Analyzed
6.8EPSS 0.004