Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/webkul/bagisto

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-75081 is a medium severity vulnerability in Webkul Bagisto up to version 2.4.4. It involves manipulation of parameters (rma_qty, resolution_type, rma_reason_id) in the /customer/account/rma/store endpoint, resulting in enforcement of behavioral workflow. The vulnerability can be exploited remotely without user interaction. The vendor has acknowledged the issue, stating some fixes have been applied and others are planned for future releases. No public patch is currently confirmed.

Join the discussion

CVE-2026-19996 is a medium severity vulnerability in Webkul Bagisto up to version 2.4.4 involving improper privilege management in the backend customer behavior data endpoint. The flaw allows remote attackers to manipulate an ID argument in the /admin/customers component, potentially leading to unauthorized privilege escalation. The vendor has acknowledged the issue and states that some fixes have already been implemented internally, with remaining fixes planned for upcoming releases. No official patch or public fix is currently confirmed.

Join the discussion

A security vulnerability (CVE-2026-19838) exists in Webkul Bagisto versions prior to 2.4.5 affecting the backend reporting endpoint at /admin/reporting/sales/. This vulnerability allows an attacker with some privileges to bypass authorization controls remotely. The vendor has acknowledged the issue and is addressing it through their internal security processes, with some fixes already implemented and others planned for upcoming releases. The vulnerability has a low severity score and no known exploits are currently active in the wild.

Join the discussion

A vulnerability in Webkul Bagisto up to version 2.4.4 affects the Customer Item Deletion Endpoint, leading to improper access controls. The issue can be exploited remotely and the exploit code is publicly available. The vendor has acknowledged the issue, stating it was identified internally prior to public disclosure and is being addressed through their security and development lifecycle, with some fixes already implemented and others planned for upcoming releases. The vulnerability has a low severity rating.

Join the discussion

CVE-2026-60120 is a stored cross-site scripting (XSS) vulnerability in Webkul Bagisto versions before 2.4.4. It arises from improper neutralization of input during web page generation, specifically via client-side template injection. An unauthenticated attacker can exploit this by registering a customer account with malicious JavaScript payloads in the first or last name fields. The vulnerability occurs because the create.blade.php template renders these fields without the Vue.js v-pre directive, causing Vue.js to execute stored template expressions as live JavaScript when an administrator views the Create Order page for that customer. This can lead to arbitrary JavaScript execution in administrator browsers.

Join the discussion

This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by sending crafted path traversal sequences through the filename parameter to access arbitrary files outside the intended directory on the targeted system. Successful exploitation of this vulnerability could allow an attacker to read arbitrary sensitive files on the targeted system.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/webkul/bagisto
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses