VYPR

Bagisto

by Webkul

Source repositories

CVEs (36)

  • CVE-2024-27499MedMar 1, 2024
    risk 0.35cvss 6.5epss 0.01

    Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

  • CVE-2026-19994MedAug 17, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization…

  • CVE-2025-62416MedOct 16, 2025
    risk 0.26cvss 5.1epss 0.00

    Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with…

  • CVE-2026-19997MedAug 17, 2026
    risk 0.24cvss 4.7epss 0.00

    A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to…

  • CVE-2026-19834MedAug 14, 2026
    risk 0.24cvss 4.7epss 0.00

    A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can…

  • CVE-2023-36236MedJan 16, 2024
    risk 0.24cvss 4.8epss 0.01

    Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.

  • CVE-2026-75082MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It…

  • CVE-2026-75081MedAug 18, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed…

  • CVE-2026-19996MedAug 17, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack…

  • CVE-2026-19993MedAug 17, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The…

  • CVE-2026-19838MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is…

  • CVE-2026-19836MedAug 14, 2026
    risk 0.21cvss 4.3epss 0.00

    A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization…

  • CVE-2026-19835LowAug 14, 2026
    risk 0.18cvss 3.8epss 0.00

    A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is…

  • CVE-2026-19995LowAug 17, 2026
    risk 0.16cvss 3.5epss 0.00

    A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the…

  • CVE-2026-19837LowAug 14, 2026
    risk 0.11cvss 2.7epss 0.00

    A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched…

  • CVE-2019-14933HigAug 11, 2019
    risk 0.00cvss 8.8epss 0.01

    Bagisto 0.1.5 allows CSRF under /admin URIs.

Page 2 of 2