Webkul
Webkul Bagisto: vulnerabilidades y CVE
Webkul Bagisto tiene 41 vulnerabilidades publicadas, 33 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE41
Últimos 12 meses33
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-101139 | Baja (2) | 0.32% | — | 28 sept 2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a… |
| CVE-2026-79411 | Alta (8.8) | 0.45% | — | 15 sept 2026 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The… |
| CVE-2026-79410 | Alta (8.1) | 0.39% | — | 15 sept 2026 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods. |
| CVE-2026-79409 | Media (6.5) | 0.46% | — | 15 sept 2026 | An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components. |
| CVE-2026-75082 | Baja (2.1) | 0.45% | — | 18 ago 2026 | A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the… |
| CVE-2026-75081 | Baja (2.1) | 0.37% | — | 18 ago 2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in… |
| CVE-2026-19997 | Baja (2) | 0.43% | — | 17 ago 2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation… |
| CVE-2026-19996 | Baja (2.1) | 0.38% | — | 17 ago 2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the… |
| CVE-2026-19995 | Baja (2) | 0.33% | — | 17 ago 2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message… |
| CVE-2026-19994 | Baja (2.1) | 0.40% | — | 17 ago 2026 | A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The… |
| CVE-2026-19993 | Baja (2.1) | 0.37% | — | 17 ago 2026 | A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The… |
| CVE-2026-19838 | Baja (2.1) | 0.41% | — | 14 ago 2026 | A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads… |
| CVE-2026-19837 | Baja (2) | 0.41% | — | 14 ago 2026 | A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to… |
| CVE-2026-19836 | Baja (2.1) | 0.41% | — | 14 ago 2026 | A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a… |
| CVE-2026-19835 | Baja (2) | 0.45% | — | 14 ago 2026 | A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access… |
| CVE-2026-19834 | Baja (2) | 0.43% | — | 14 ago 2026 | A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of… |
| CVE-2026-60120 | Media (5.1) | 0.36% | — | 9 jul 2026 | Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering… |
| CVE-2026-9506 | Alta (8.7) | 1.8% | — | 8 jun 2026 | This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path… |
| CVE-2026-6745 | Baja (2) | 0.33% | — | 21 abr 2026 | A vulnerability was determined in Bagisto up to 2.3.15. Affected by this vulnerability is an unknown functionality of the component Custom Scripts Handler. This manipulation causes cross site scripting. Remote… |
| CVE-2026-6744 | Baja (2.1) | 0.35% | — | 21 abr 2026 | A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely.… |
| CVE-2026-21451 | Media (5.2) | 0.56% | — | 2 ene 2026 | Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to… |
| CVE-2026-21450 | Alta (7.3) | 1.4% | — | 2 ene 2026 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation.… |
| CVE-2026-21449 | Alta (7.4) | 0.51% | — | 2 ene 2026 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege user. Version 2.3.10 fixes the issue. |
| CVE-2026-21448 | Alta (8.9) | 0.92% | — | 2 ene 2026 | Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `add address` step they can inject a… |
| CVE-2026-21447 | Alta (7.1) | 0.30% | — | 2 ene 2026 | Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from… |
| CVE-2026-21446 | Alta (8.8) | 0.63% | — | 2 ene 2026 | Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`)… |
| CVE-2025-62418 | Media (4.8) | 0.28% | — | 16 oct 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded… |
| CVE-2025-62417 | Alta (7.1) | 0.39% | — | 16 oct 2025 | Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported or saved into a CSV and opened in… |
| CVE-2025-62416 | Media (6.8) | 0.40% | — | 16 oct 2025 | Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when… |
| CVE-2025-62415 | Media (4.8) | 0.28% | — | 16 oct 2025 | Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted HTML file containing… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.