VYPR

Bagisto CVE

by Isukasanuj

Source repositories

CVEs (3)

  • CVE-2026-79410HigSep 15, 2026
    risk 0.46cvss 8.1epss

    Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

  • CVE-2026-79409MedSep 15, 2026
    risk 0.35cvss 6.5epss

    An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.

  • CVE-2026-79411Sep 15, 2026
    risk 0.00cvss epss

    Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update,…