PT-2026-76885 · Webkul · Bagisto

·

CVE-2026-75082

·

Published

2026-08-18

·

Updated

2026-08-18

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Webkul Bagisto versions prior to 2.4.5
Description A flaw in the Customer-Registration Notification Email component allows remote attackers to perform basic cross site scripting (XSS), a technique where malicious scripts are injected into trusted websites. The issue exists within an unknown function of the /customer/register file and is triggered by manipulating the first name and last name variables.
Recommendations Update to a version newer than 2.4.4. As a temporary mitigation, restrict or sanitize the input for the first name and last name variables in the /customer/register endpoint.

Exploit

Fix

Special Elements Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75082

Affected Products

Bagisto