Junglewise Threat Intelligence

CVE-2026-21451: Bagisto has HTML Filter Bypass that Enables Stored XSS

CVE-2026-21451 · Severity: medium · CVSS 4 · Published 2026-01-02

Technologies: bagisto/bagisto (Packagist). Vendors: Packagist.

Executive brief

Bagisto has HTML Filter Bypass that Enables Stored XSS

Affected products

  • Packagist bagisto/bagisto

Related threats