Technology · Packagist
bagisto/bagisto (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 20 vulnerabilities in bagisto/bagisto (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-6744, was published on 21 April 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest bagisto/bagisto (Packagist) vulnerabilities
- CVE-2026-6744: Bagisto affected by Server-Side Request ForgerylowCVSS 3.1EPSS 0.4%
- CVE-2026-6745: Bagisto affected by Cross-site ScriptinglowCVSS 3.1EPSS 0.3%
- CVE-2026-21449: Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege userslowCVSS 3.1EPSS 0.5%
- CVE-2026-21447: Bagisto has IDOR in Customer Order Reorder FunctionalitylowCVSS 3.1EPSS 0.3%
- CVE-2026-21448: Bagisto has Normal & Blind SSTI from low-privilege user when ordering productlowCVSS 3.1EPSS 0.9%
- CVE-2026-21450: Bagisto SSTI vulnerability in type parameter can lead to RCEmediumCVSS 4EPSS 1.4%
- CVE-2026-21451: Bagisto has HTML Filter Bypass that Enables Stored XSSmediumCVSS 4EPSS 0.6%
- CVE-2026-21446: Bagisto Missing Authentication on Installer API EndpointslowCVSS 3.1EPSS 0.6%
- CVE-2025-62414: bagisto has Cross Site Scripting (XSS) in Create New CustomerlowCVSS 3.1EPSS 0.3%
- CVE-2025-62417: bagisto has CSV Formula Injection in Create New ProductlowCVSS 3.1EPSS 0.4%
- CVE-2025-62418: bagisto has a Cross Site Scripting (XSS) vulnerability in TinyMCE Image Upload (SVG)lowCVSS 3.1EPSS 0.3%
- CVE-2025-62416: bagisto has Server Side Template Injection (SSTI) in Product DescriptionlowCVSS 3.1EPSS 0.4%
- CVE-2025-62415: bagisto has Cross Site Scripting (XSS) issue in TinyMCE Image Upload (HTML)lowCVSS 3.1EPSS 0.3%
- CVE-2025-60880: Bagisto is vulnerable to XSS through Admin Panel's product creation pathlowCVSS 3.1EPSS 0.4%
- CVE-2023-36238: Bagisto vulnerable to Insecure Direct Object Reference (IDOR)lowCVSS 3.1EPSS 0.5%
- CVE-2024-27499: Bagist Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2023-36237: Bagisto Cross-Site Request Forgery vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2023-36236: Cross-site Scripting in BagistolowCVSS 3.1EPSS 0.6%
- CVE-2019-14933: Bagisto CSRF VulnerabilitylowCVSS 3EPSS 0.6%
- CVE-2019-16403: Authorization Bypass Through User-Controlled Key in BagistolowCVSS 3.1EPSS 1.4%
Most severe bagisto/bagisto (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-21450: Bagisto SSTI vulnerability in type parameter can lead to RCEmediumCVSS 4EPSS 1.4%
- CVE-2026-21451: Bagisto has HTML Filter Bypass that Enables Stored XSSmediumCVSS 4EPSS 0.6%
- CVE-2019-16403: Authorization Bypass Through User-Controlled Key in BagistolowCVSS 3.1EPSS 1.4%
- CVE-2026-21448: Bagisto has Normal & Blind SSTI from low-privilege user when ordering productlowCVSS 3.1EPSS 0.9%
- CVE-2026-21446: Bagisto Missing Authentication on Installer API EndpointslowCVSS 3.1EPSS 0.6%
- CVE-2023-36236: Cross-site Scripting in BagistolowCVSS 3.1EPSS 0.6%
- CVE-2023-36238: Bagisto vulnerable to Insecure Direct Object Reference (IDOR)lowCVSS 3.1EPSS 0.5%
- CVE-2026-21449: Bagisto is vulnerable to SSTI via name parameters provided by non-admin low-privilege userslowCVSS 3.1EPSS 0.5%
- CVE-2024-27499: Bagist Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.5%
- CVE-2025-60880: Bagisto is vulnerable to XSS through Admin Panel's product creation pathlowCVSS 3.1EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/bagisto-bagisto.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "bagisto/bagisto (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/bagisto-bagisto, 28 September 2026.