Bagisto

Vendor:

First CVE: Aug 11, 2019 · Active for 6 years

22
Total CVEs
More Total CVEs than 95% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Bagisto over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 2019
6 years ago
Most Recent CVE
Jul 9, 2026
19 days ago

CVE Severity & Scoring

Bagisto22 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (40.9%)
Unknown0 (0.0%)
Required13 (59.1%)
Privileges Required
Low7 (31.8%)
High7 (31.8%)
None8 (36.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code ex
Jan 2, 20269.834NONO
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The under
Jan 2, 20269.830NONO
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the `
Jan 2, 20269.828NONO
In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers.
Sep 18, 20198.828NONO
Bagisto 0.1.5 allows CSRF under /admin URIs.
Aug 11, 20198.828NONO
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Althou
Jan 2, 20268.427NONO
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious Ja
Oct 10, 20258.326NONO
Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript i
Jul 9, 20265.425NONO
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege us
Jan 2, 20268.825NONO
Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported
Oct 16, 20257.825NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Bagisto

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.755.80.3%00
2.3.627.40.4%00
1.5.137.30.7%00
0.1.518.80.6%00