CVE-2026-21450 Details
Description
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.
A server-side template injection vulnerability has been identified in Bagisto, an open-source Laravel eCommerce platform. This issue affects versions prior to 2.3.10 and arises from the type parameter, allowing for remote code execution or other forms of exploitation. The vulnerability can be reproduced by accessing a specific URL that includes a crafted type parameter, which is then processed by the server-side template engine.
Users can upgrade to Bagisto version 2.3.10 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/bagisto/bagisto/security/advisories/GHSA-9hvg-qw5q-wqwp | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| webkul bagisto | < 2.3.10 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 8, 2026 | Initial Analysis | [email protected] |
| Jan 2, 2026 | New CVE Received | [email protected] |