Bagisto Webkul Bagisto

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Webkul Bagisto.

By the Year

In 2026 there have been 14 vulnerabilities in Webkul Bagisto with an average score of 5.2 out of ten. Bagisto did not have any published security vulnerabilities last year. That is, 14 more vulnerabilities have already been reported in 2026 as compared to last year.




Year Vulnerabilities Average Score
2026 14 5.23
2025 0 0.00
2024 4 4.80
2023 1 8.80
2022 0 0.00
2021 0 0.00
2020 0 0.00
2019 2 8.80

It may take a day or so for new Bagisto vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Webkul Bagisto Security Vulnerabilities

Bagisto 2.4.4 XSS in Customer-Registration Email (first_name/last_name)
CVE-2026-75082 5.3 - Medium - August 18, 2026

A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Basic XSS

Webkul Bagisto <=2.4.4 RMA Argument Manipulation (Remote)
CVE-2026-75081 5.3 - Medium - August 17, 2026

A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Improper Enforcement of Behavioral Workflow

Bagisto <=2.4.4 RMA Endpoint Auth Byp @ /admin/sales/rma/requests
CVE-2026-19997 5.1 - Medium - August 17, 2026

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Insecure Direct Object Reference / IDOR

Bagisto <=2.4.4: /admin/customers Improper Privilege Escalation (Remote)
CVE-2026-19996 5.3 - Medium - August 17, 2026

A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Improper Privilege Management

Webkul Bagisto <=2.4.4 RMA Message Handler XSS
CVE-2026-19995 5.1 - Medium - August 17, 2026

A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

XSS

Auth Bypass in Bagisto 2.4.4 via Config Mgmt 'action'
CVE-2026-19994 5.3 - Medium - August 17, 2026

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Insecure Direct Object Reference / IDOR

Webkul Bagisto <=2.4.4 RMA State Validation Remote Workflow Exploitation
CVE-2026-19993 5.3 - Medium - August 17, 2026

A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Improper Enforcement of Behavioral Workflow

Bagisto <2.4.4 Auth Bypass via Backend Reporting Endpoint
CVE-2026-19838 5.3 - Medium - August 14, 2026

A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Insecure Direct Object Reference / IDOR

Bagisto 2.4.4 Customer Search Info Disclosure via Query Param
CVE-2026-19837 5.1 - Medium - August 14, 2026

A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Information Disclosure

Bagisto <=2.4.4 Auth Bypass via /admin/customers/view ID
CVE-2026-19836 5.3 - Medium - August 14, 2026

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Insecure Direct Object Reference / IDOR

Webkul Bagisto 2.4.4 Improper Access Control in Customer Item Deletion Endpoint
CVE-2026-19835 5.1 - Medium - August 14, 2026

A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Authorization

Webkul Bagisto <=2.4.4 AdminCustomerImpersonation Auth Bypass via ID
CVE-2026-19834 5.1 - Medium - August 14, 2026

A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Insecure Direct Object Reference / IDOR

Bagisto 2.4.3 XSS via clientside template injection in create.blade.php
CVE-2026-60120 5.4 - Medium - July 09, 2026

Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php template renders customer name fields without the Vue.js v-pre directive, causing Vue.js to evaluate stored template expressions as live JavaScript when an administrator opens the Create Order page for the affected customer.

XSS

Bagisto ImageCacheController Path Traversal Remote File Read
CVE-2026-9506 - June 08, 2026

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system. Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.

Directory traversal

Bagisto 1.5.1 IDOR via Invoice ID Parameter
CVE-2023-36238 - March 13, 2024

Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.

Bagisto 1.5.1 XSS via PNG upload in product review
CVE-2024-27499 - March 01, 2024

Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.

Bagisto <=1.5.1 CSRF allows arbitrary code execution
CVE-2023-36237 - February 26, 2024

Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.

Bagisto XSS via SVG Upload (v1.5.0)
CVE-2023-36236 4.8 - Medium - January 16, 2024

Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.

XSS

Bagisto v1.5.1 SSTI Vulnerability
CVE-2023-33570 8.8 - High - June 28, 2023

Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).

In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc
CVE-2019-16403 8.8 - High - September 18, 2019

In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.

Insecure Direct Object Reference / IDOR

Bagisto 0.1.5 allows CSRF under /admin URIs.
CVE-2019-14933 - August 11, 2019

Bagisto 0.1.5 allows CSRF under /admin URIs.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Webkul Bagisto or by Webkul? Click the Watch button to subscribe.

Webkul
Vendor

subscribe