Bagisto
by Webkul
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36236 | Med | 0.24 | 4.8 | 0.01 | Jan 16, 2024 | Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. | ||
| CVE-2026-19838 | Med | 0.21 | 4.3 | — | Aug 14, 2026 | A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is… | ||
| CVE-2026-19836 | Med | 0.21 | 4.3 | — | Aug 14, 2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization… | ||
| CVE-2026-19835 | Low | 0.18 | 3.8 | — | Aug 14, 2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is… | ||
| CVE-2026-19837 | Low | 0.11 | 2.7 | — | Aug 14, 2026 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched… | ||
| CVE-2019-14933 | Hig | 0.00 | 8.8 | 0.01 | Aug 11, 2019 | Bagisto 0.1.5 allows CSRF under /admin URIs. |
- risk 0.24cvss 4.8epss 0.01
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
- risk 0.21cvss 4.3epss —
A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is…
- risk 0.21cvss 4.3epss —
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization…
- risk 0.18cvss 3.8epss —
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is…
- risk 0.11cvss 2.7epss —
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched…
- risk 0.00cvss 8.8epss 0.01
Bagisto 0.1.5 allows CSRF under /admin URIs.
Page 2 of 2