CVE-2025-60880

HIGH

Bagisto 2.3.6 - Authenticated XSS

Title source: llm
STIX 2.1

Description

An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.

References (2)

Core 2

Scores

CVSS v3 8.3
EPSS 0.0001
EPSS Percentile 3.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
bagisto/bagisto 2.3.6 - 2.3.7Packagist
webkul/bagisto 2.3.6
Published Oct 10, 2025
Tracked Since Feb 18, 2026