Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Webkul — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting Webkul. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Webkul develops e-commerce and marketplace solutions, primarily for Magento and Shopify platforms, enabling businesses to create online stores and marketplaces. Historically, their products have been vulnerable to multiple security issues, including remote code execution, cross-site scripting, and privilege escalation vulnerabilities, as evidenced by their 8 recorded CVEs. These vulnerabilities often stem from insufficient input validation and improper access controls in their extensions. While no major public security incidents have been widely reported, the consistent pattern of vulnerabilities in their products suggests a need for improved security development practices to protect their customers' environments from potential exploitation.

Found 14 results / 27 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2026-75082 Webkul Bagisto Customer-Registration Notification Email register cross site scripting — Bagisto CWE-80 4.3 Medium 2026-08-18
CVE-2026-75081 Webkul Bagisto store behavioral workflow — Bagisto CWE-841 4.3 Medium 2026-08-17
CVE-2026-19997 Webkul Bagisto Backend Sales RMA Endpoint requests authorization — Bagisto CWE-639 4.7 Medium 2026-08-17
CVE-2026-19996 Webkul Bagisto Backend Customer Behavior Data Endpoint customers privileges management — Bagisto CWE-269 4.3 Medium 2026-08-17
CVE-2026-19995 Webkul Bagisto RMA Message send-message cross site scripting — Bagisto CWE-79 3.5 Low 2026-08-17
CVE-2026-19994 Webkul Bagisto Configuration Management execute authorization — Bagisto CWE-639 6.3 Medium 2026-08-17
CVE-2026-19993 Webkul Bagisto RMA State Validation update-status behavioral workflow — Bagisto CWE-841 4.3 Medium 2026-08-17
CVE-2026-19838 Webkul Bagisto Backend Reporting Endpoint sales authorization — Bagisto CWE-639 4.3 Medium 2026-08-14
CVE-2026-19837 Webkul Bagisto Customer Search search information disclosure — Bagisto CWE-200 2.7 Low 2026-08-14
CVE-2026-19836 Webkul Bagisto Backend Customer Detail Feature view authorization — Bagisto CWE-639 4.3 Medium 2026-08-14
CVE-2026-19835 Webkul Bagisto Customer Item Deletion Endpoint access control — Bagisto CWE-284 3.8 Low 2026-08-14
CVE-2026-19834 Webkul Bagisto Admin Customer Impersonation Feature login-as-customer authorization — Bagisto CWE-639 4.7 Medium 2026-08-14
CVE-2026-60120 Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php — Bagisto CWE-79 5.4 Medium 2026-07-09
CVE-2026-9506 Path Traversal Vulnerability in Bagisto — Bagisto CWE-22 - - 2026-06-08

This page lists every published CVE security advisory associated with Webkul. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.