Bagisto
Vendor:
First CVE: Aug 11, 2019 · Active for 6 years
22
Total CVEs
More Total CVEs than 95% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.4
Avg CVSS
Higher Avg CVSS than 51% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Bagisto over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 11, 2019
6 years ago
Most Recent CVE
Jul 9, 2026
19 days ago
CVE Severity & Scoring
Bagisto22 CVEs
45%
41%
14%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.5%)
Network21 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (40.9%)
Unknown0 (0.0%)
Required13 (59.1%)
Privileges Required
Low7 (31.8%)
High7 (31.8%)
None8 (36.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-21450CRITICAL Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code ex | Jan 2, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-21446CRITICAL Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The under | Jan 2, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-21448CRITICAL Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal customer orders any product, in the ` | Jan 2, 2026 | 9.8 | 28 | NO | NO |
CVE-2019-16403HIGH In Webkul Bagisto before 0.1.5, the functionalities for customers to change their own values (such as address, review, orders, etc.) can also be manipulated by other customers. | Sep 18, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-14933HIGH Bagisto 0.1.5 allows CSRF under /admin URIs. | Aug 11, 2019 | 8.8 | 28 | NO | NO |
CVE-2026-21451HIGH Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Althou | Jan 2, 2026 | 8.4 | 27 | NO | NO |
CVE-2025-60880HIGH An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious Ja | Oct 10, 2025 | 8.3 | 26 | NO | NO |
CVE-2026-60120MEDIUM Bagisto before 2.4.4 contains a stored cross-site scripting vulnerability via client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript i | Jul 9, 2026 | 5.4 | 25 | NO | NO |
CVE-2026-21449HIGH Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and last name from a low-privilege us | Jan 2, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-62417HIGH Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) is accepted and later exported | Oct 16, 2025 | 7.8 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Bagisto
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.7 | 5 | 5.8 | 0.3% | 0 | 0 |
| 2.3.6 | 2 | 7.4 | 0.4% | 0 | 0 |
| 1.5.1 | 3 | 7.3 | 0.7% | 0 | 0 |
| 0.1.5 | 1 | 8.8 | 0.6% | 0 | 0 |