CVE-2026-75082: Basic Cross Site Scripting in Webkul Bagisto
CVE-2026-75082 is a basic cross-site scripting (XSS) vulnerability in Webkul Bagisto affecting versions 2.4.0 through 2.4.4. The flaw exists in the /customer/register component related to Customer-Registration Notification Email, where manipulation of the first_name or last_name parameters can lead to XSS. The vulnerability can be exploited remotely without authentication. The vendor has acknowledged the issue, stating that some fixes have already been implemented internally and remaining fixes are planned for future releases. The CVSS 4.0 score rates this vulnerability as medium severity.
AI Analysis
Technical Summary
A basic cross-site scripting vulnerability (CVE-2026-75082) affects Webkul Bagisto versions 2.4.0 to 2.4.4 in the /customer/register endpoint of the Customer-Registration Notification Email component. The vulnerability arises from improper handling of the first_name and last_name input parameters, allowing an attacker to inject malicious scripts. This flaw can be exploited remotely without privileges or user interaction. The vendor has internally identified and partially addressed the issue prior to public disclosure, with remaining fixes planned in upcoming releases. No official patch links are provided yet.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser when interacting with the affected component. This may lead to session hijacking, defacement, or other client-side attacks. However, the impact is limited to a medium severity level as per CVSS 4.0, indicating no direct system compromise or data loss is implied.
Mitigation Recommendations
The vendor has confirmed that some fixes have already been applied internally and that remaining issues are planned to be resolved in future product releases. No official patches or updates are currently publicly available. Users should monitor vendor communications for upcoming releases addressing this vulnerability. Until then, consider applying input validation or sanitization on the affected parameters as a temporary mitigation.
CVE-2026-75082: Basic Cross Site Scripting in Webkul Bagisto
Description
CVE-2026-75082 is a basic cross-site scripting (XSS) vulnerability in Webkul Bagisto affecting versions 2.4.0 through 2.4.4. The flaw exists in the /customer/register component related to Customer-Registration Notification Email, where manipulation of the first_name or last_name parameters can lead to XSS. The vulnerability can be exploited remotely without authentication. The vendor has acknowledged the issue, stating that some fixes have already been implemented internally and remaining fixes are planned for future releases. The CVSS 4.0 score rates this vulnerability as medium severity.
CVSS v4.0
Score 5.3medium
Affected software
Webkul
Bagisto
pkg:composer/webkul/bagistocpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
A basic cross-site scripting vulnerability (CVE-2026-75082) affects Webkul Bagisto versions 2.4.0 to 2.4.4 in the /customer/register endpoint of the Customer-Registration Notification Email component. The vulnerability arises from improper handling of the first_name and last_name input parameters, allowing an attacker to inject malicious scripts. This flaw can be exploited remotely without privileges or user interaction. The vendor has internally identified and partially addressed the issue prior to public disclosure, with remaining fixes planned in upcoming releases. No official patch links are provided yet.
Potential Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary scripts in the context of the victim's browser when interacting with the affected component. This may lead to session hijacking, defacement, or other client-side attacks. However, the impact is limited to a medium severity level as per CVSS 4.0, indicating no direct system compromise or data loss is implied.
Mitigation Recommendations
The vendor has confirmed that some fixes have already been applied internally and that remaining issues are planned to be resolved in future product releases. No official patches or updates are currently publicly available. Users should monitor vendor communications for upcoming releases addressing this vulnerability. Until then, consider applying input validation or sanitization on the affected parameters as a temporary mitigation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-08-17T16:16:27.594Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a83a6c4bf8831d539d92480
Added to database: 08/18/2026, 00:26:44 UTC
Last enriched: 09/11/2026, 23:50:32 UTC
Last updated: 10/01/2026, 14:51:10 UTC
Views: 53
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.