Home/Product/webkul bagisto
Product

webkul bagisto

21 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-21451
< 2.3.10
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to
8.4HIGH
CVE-2026-21450
< 2.3.10
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection vi
9.8CRITICAL
CVE-2026-21449
< 2.3.10
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection vi
8.8HIGH
CVE-2026-21448
< 2.3.10
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. W
9.8CRITICAL
CVE-2026-21447
< 2.3.10
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability i
7.1HIGH
CVE-2026-21446
>= 2.3.0 and < 2.3.10
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even
9.8CRITICAL
CVE-2025-62418
all versions
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker
6.9MEDIUM
CVE-2025-62417
all versions
Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for exam
7.8HIGH
CVE-2025-62416
all versions
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to
5.1MEDIUM
CVE-2025-62415
all versions
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker
6.9MEDIUM
CVE-2025-62414
all versions
Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel
6.9MEDIUM
CVE-2025-60880
all versions
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to
8.3HIGH
CVE-2025-56426
all versions
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specificall
6.5MEDIUM
CVE-2025-40675
>= 2.0.0 and < 2.2.3
A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to ex
6.1MEDIUM
CVE-2023-36238
all versions
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID p
6.5MEDIUM
CVE-2024-27499
all versions
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
6.5MEDIUM
CVE-2023-36237
< 1.5.1
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML
8.8HIGH
CVE-2023-36236
<= 1.5.0
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted
4.8MEDIUM
CVE-2023-33570
all versions
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
8.8HIGH
CVE-2019-16403
< 0.1.5
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc
8.8HIGH
CVE-2019-14933
all versions
Bagisto 0.1.5 allows CSRF under /admin URIs.
8.8HIGH
threatengine.sh