Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.63% | — | Webkul Bagisto | 2/1/2026 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker can bypass the Ib… | |
| Analizada | Media (4.8) | 0.28% | — | Webkul Bagisto | 16/10/2025 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser.… | |
| Analizada | Alta (7.1) | 0.39% | — | Webkul Bagisto | 16/10/2025 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in spreadsheet software, the spreadsheet will interpret that cell as a formula. This allows an attacker to… | |
| Analizada | Media (6.8) | 0.40% | — | Webkul Bagisto | 16/10/2025 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with product creation privileges to inject… | |
| Analizada | Media (4.8) | 0.28% | — | Webkul Bagisto | 16/10/2025 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser.… | |
| Analizada | Media (4.8) | 0.28% | — | Webkul Bagisto | 16/10/2025 | 17/6/2026 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the “Create New Customer” feature (in the admin panel) is vulnerable to Cross-Site Scripting (XSS). An attacker with access to the admin create-customer form can inject malicious JavaScript payloads into certain input fields. These payloads may… | |
| Analizada | Alta (8.3) | 0.41% | 💥 PoC | Webkul Bagisto | 10/10/2025 | 17/6/2026 | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser,… | |
| Analizada | Media (6.5) | 0.41% | — | Webkul Bagisto | 9/10/2025 | 17/6/2026 | An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly. | |
| Analizada | Media (5.1) | 0.23% | — | Webkul Bagisto | 9/6/2025 | 17/6/2026 | A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by sending the victim a malicious URL using the parameter 'query' in '/search'. This vulnerability can be exploited to steal sensitive user… | |
| Analizada | Media (6.5) | 0.54% | — | Webkul Bagisto | 13/3/2024 | 17/6/2026 | Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter. | |
| Modificada | Media (6.5) | 0.52% | — | Webkul Bagisto | 1/3/2024 | 17/6/2026 | Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option. | |
| Analizada | Alta (8.8) | 0.39% | — | Webkul Bagisto | 26/2/2024 | 17/6/2026 | Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script. | |
| Modificada | Media (4.8) | 0.61% | — | Webkul Bagisto | 16/1/2024 | 17/6/2026 | Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad. | |
| Modificada | Alta (8.8) | 1.1% | — | Webkul Bagisto | 28/6/2023 | 17/6/2026 | Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI). | |
| Modificada | Alta (8.8) | 1.4% | — | Webkul Bagisto | 18/9/2019 | 17/6/2026 | In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers. | |
| Modificada | Alta (8.8) | 0.60% | — | Webkul Bagisto | 11/8/2019 | 17/6/2026 | Bagisto 0.1.5 allows CSRF under /admin URIs. |