Webkul Bagisto
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Webkul Bagisto.
By the Year
In 2026 there have been 14 vulnerabilities in Webkul Bagisto with an average score of 5.2 out of ten. Bagisto did not have any published security vulnerabilities last year. That is, 14 more vulnerabilities have already been reported in 2026 as compared to last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 14 | 5.23 |
| 2025 | 0 | 0.00 |
| 2024 | 4 | 4.80 |
| 2023 | 1 | 8.80 |
| 2022 | 0 | 0.00 |
| 2021 | 0 | 0.00 |
| 2020 | 0 | 0.00 |
| 2019 | 2 | 8.80 |
It may take a day or so for new Bagisto vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Webkul Bagisto Security Vulnerabilities
Bagisto 2.4.4 XSS in Customer-Registration Email (first_name/last_name)
CVE-2026-75082
5.3 - Medium
- August 18, 2026
A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Basic XSS
Webkul Bagisto <=2.4.4 RMA Argument Manipulation (Remote)
CVE-2026-75081
5.3 - Medium
- August 17, 2026
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Improper Enforcement of Behavioral Workflow
Bagisto <=2.4.4 RMA Endpoint Auth Byp @ /admin/sales/rma/requests
CVE-2026-19997
5.1 - Medium
- August 17, 2026
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the file /admin/sales/rma/requests of the component Backend Sales RMA Endpoint. Performing a manipulation results in authorization bypass. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Insecure Direct Object Reference / IDOR
Bagisto <=2.4.4: /admin/customers Improper Privilege Escalation (Remote)
CVE-2026-19996
5.3 - Medium
- August 17, 2026
A vulnerability was identified in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/customers of the component Backend Customer Behavior Data Endpoint. Such manipulation of the argument ID leads to improper privilege management. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Improper Privilege Management
Webkul Bagisto <=2.4.4 RMA Message Handler XSS
CVE-2026-19995
5.1 - Medium
- August 17, 2026
A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
XSS
Auth Bypass in Bagisto 2.4.4 via Config Mgmt 'action'
CVE-2026-19994
5.3 - Medium
- August 17, 2026
A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Insecure Direct Object Reference / IDOR
Webkul Bagisto <=2.4.4 RMA State Validation Remote Workflow Exploitation
CVE-2026-19993
5.3 - Medium
- August 17, 2026
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Improper Enforcement of Behavioral Workflow
Bagisto <2.4.4 Auth Bypass via Backend Reporting Endpoint
CVE-2026-19838
5.3 - Medium
- August 14, 2026
A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Insecure Direct Object Reference / IDOR
Bagisto 2.4.4 Customer Search Info Disclosure via Query Param
CVE-2026-19837
5.1 - Medium
- August 14, 2026
A weakness has been identified in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /admin/customers/search of the component Customer Search. Executing a manipulation of the argument Query can lead to information disclosure. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Information Disclosure
Bagisto <=2.4.4 Auth Bypass via /admin/customers/view ID
CVE-2026-19836
5.3 - Medium
- August 14, 2026
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Insecure Direct Object Reference / IDOR
Webkul Bagisto 2.4.4 Improper Access Control in Customer Item Deletion Endpoint
CVE-2026-19835
5.1 - Medium
- August 14, 2026
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Authorization
Webkul Bagisto <=2.4.4 AdminCustomerImpersonation Auth Bypass via ID
CVE-2026-19834
5.1 - Medium
- August 14, 2026
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Insecure Direct Object Reference / IDOR
Bagisto 2.4.3 XSS via clientside template injection in create.blade.php
CVE-2026-60120
5.4 - Medium
- July 09, 2026
Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers by registering a customer account with malicious payload in the first or last name field. The create.blade.php template renders customer name fields without the Vue.js v-pre directive, causing Vue.js to evaluate stored template expressions as live JavaScript when an administrator opens the Create Order page for the affected customer.
XSS
Bagisto ImageCacheController Path Traversal Remote File Read
CVE-2026-9506
- June 08, 2026
This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system. Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.
Directory traversal
Bagisto 1.5.1 IDOR via Invoice ID Parameter
CVE-2023-36238
- March 13, 2024
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
Bagisto 1.5.1 XSS via PNG upload in product review
CVE-2024-27499
- March 01, 2024
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
Bagisto <=1.5.1 CSRF allows arbitrary code execution
CVE-2023-36237
- February 26, 2024
Cross Site Request Forgery vulnerability in Bagisto before v.1.5.1 allows an attacker to execute arbitrary code via a crafted HTML script.
Bagisto XSS via SVG Upload (v1.5.0)
CVE-2023-36236
4.8 - Medium
- January 16, 2024
Cross Site Scripting vulnerability in webkil Bagisto v.1.5.0 and before allows an attacker to execute arbitrary code via a crafted SVG file uplad.
XSS
Bagisto v1.5.1 SSTI Vulnerability
CVE-2023-33570
8.8 - High
- June 28, 2023
Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc
CVE-2019-16403
8.8 - High
- September 18, 2019
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
Insecure Direct Object Reference / IDOR
Bagisto 0.1.5 allows CSRF under /admin URIs.
CVE-2019-14933
- August 11, 2019
Bagisto 0.1.5 allows CSRF under /admin URIs.
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Webkul Bagisto or by Webkul? Click the Watch button to subscribe.