Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Bagisto — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in Bagisto, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the Bagisto e-commerce platform, specifically addressing weaknesses within the open-source Magento-based framework. It collects records of disclosed security issues, such as cross-site scripting, SQL injection, and authentication flaws, covering advisories published over the most recent two years. You can use this interface to track the vendor's advisory history, understand the distribution of weakness classes, and review the product's vulnerability timeline to assess current security posture. The dataset includes both critical and moderate severity findings, enabling users to monitor remediation status and identify recurring patterns in code vulnerabilities.

Vendor: Bagisto

CVE ID Title CVSS Severity Published
CVE-2026-101139 Webkul Bagisto Invoice Mass Status Update state authorization CWE-862 2.7 Low 2026-09-28
CVE-2026-75082 Webkul Bagisto Customer-Registration Notification Email register cross site scripting CWE-80 4.3 Medium 2026-08-18
CVE-2026-75081 Webkul Bagisto store behavioral workflow CWE-841 4.3 Medium 2026-08-17
CVE-2026-19997 Webkul Bagisto Backend Sales RMA Endpoint requests authorization CWE-639 4.7 Medium 2026-08-17
CVE-2026-19996 Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management CWE-269 4.3 Medium 2026-08-17
CVE-2026-19995 Webkul Bagisto RMA Message send-message cross site scripting CWE-79 3.5 Low 2026-08-17
CVE-2026-19994 Webkul Bagisto Configuration Management execute authorization CWE-639 6.3 Medium 2026-08-17
CVE-2026-19993 Webkul Bagisto RMA State Validation update-status behavioral workflow CWE-841 4.3 Medium 2026-08-17
CVE-2026-19838 Webkul Bagisto Backend Reporting Endpoint sales authorization CWE-639 4.3 Medium 2026-08-14
CVE-2026-19837 Webkul Bagisto Customer Search search information disclosure CWE-200 2.7 Low 2026-08-14
CVE-2026-19836 Webkul Bagisto Backend Customer Detail Feature view authorization CWE-639 4.3 Medium 2026-08-14
CVE-2026-19835 Webkul Bagisto Customer Item Deletion Endpoint access control CWE-284 3.8 Low 2026-08-14
CVE-2026-19834 Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization CWE-639 4.7 Medium 2026-08-14
CVE-2026-60120 Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php CWE-79 5.4 Medium 2026-07-09
CVE-2026-9506 Path Traversal Vulnerability in Bagisto CWE-22 - - 2026-06-08
CVE-2026-6745 Bagisto Custom Scripts cross site scripting CWE-79 3.5 Low 2026-04-21
CVE-2026-6744 Bagisto Downloadable Link copy server-side request forgery CWE-918 6.3 Medium 2026-04-21
CVE-2026-21450 Bagisto has SSTI in parameter that can lead to RCE CWE-1336 9.8 - 2026-01-02
CVE-2026-21451 Bagisto has HTML Filter Bypass that Enables Stored XSS CWE-79 5.4 - 2026-01-02
CVE-2026-21449 Bagisto has SSTI via first and last name from low-privilege user (not admin) CWE-1336 9.9 - 2026-01-02
CVE-2026-21448 Bagisto has Normal & Blind SSTI from low-privilege user when ordering product CWE-1336 8.8 - 2026-01-02
CVE-2026-21447 Bagisto has IDOR in Customer Order Reorder Functionality CWE-284 7.1 High 2026-01-02
CVE-2026-21446 Bagisto Missing Authentication on Installer API Endpoints CWE-306 9.8 - 2026-01-02
CVE-2025-62415 bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (HTML) CWE-80 6.9 Medium 2025-10-16
CVE-2025-62418 bagisto - Cross Site Scripting (XSS) in TinyMCE Image Upload (SVG) CWE-80 6.9 Medium 2025-10-16
CVE-2025-62414 bagisto - Cross Site Scripting (XSS) in Create New Customer CWE-80 6.9 Medium 2025-10-16
CVE-2025-62416 bagisto - Server Side Template Injection (SSTI) in Product Description CWE-94 5.1 Medium 2025-10-16
CVE-2025-62417 bagisto - CSV Formula Injection in Create New Product CWE-1236 7.8AI High AI 2025-10-16
CVE-2025-40675 Reflected Cross-Site Scripting (XSS) in Bagisto CWE-79 6.1AI Medium AI 2025-06-09

All 29 known CVE vulnerabilities affecting Bagisto with full Chinese analysis, references, and POCs where available.