CVE-2026-21451
HIGHBagisto < 2.3.10 - Stored Cross-Site Scripting via CMS Page Editor
Title source: llmDescription
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the filtering can be bypassed by manipulating the raw HTTP POST request before submission. As a result, arbitrary JavaScript can be stored in the CMS content and executed whenever the page is viewed or edited. This exposes administrators to a high-severity risk, including complete account takeover, backend hijacking, and malicious script execution. Version 2.3.10 fixes the issue.
References (1)
Core 1
Core References
Vendor Advisory, Exploit x_refsource_confirm
https://github.com/bagisto/bagisto/security/advisories/GHSA-2mwc-h2mg-v6p8
Scores
CVSS v3
8.4
EPSS
0.0049
EPSS Percentile
38.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
bagisto/bagisto
0 - 2.3.10Packagist
webkul/bagisto
< 2.3.10
Published
Jan 02, 2026
Tracked Since
Feb 18, 2026