CVE-2026-21451
Bagisto has HTML Filter Bypass that Enables Stored XSS
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.2EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
02 Jan 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `<script>` tags, the filtering can be bypassed by manipulating the raw HTTP POST request before submission. As a result, arbitrary JavaScript can be stored in the CMS content and executed whenever the page is viewed or edited. This exposes administrators to a high-severity risk, including complete account takeover, backend hijacking, and malicious script execution. Version 2.3.10 fixes the issue.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:P
Affected products
bagisto · bagistoWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →