Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases." | |
| Title | Webkul Bagisto Customer-Registration Notification Email register cross site scripting | |
| First Time appeared |
Webkul
Webkul bagisto |
|
| Weaknesses | CWE-74 CWE-80 |
|
| CPEs | cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul bagisto |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-18T00:00:12.707Z
Reserved: 2026-08-17T16:16:27.594Z
Link: CVE-2026-75082
No data.
Status : Received
Published: 2026-08-18T00:16:53.867
Modified: 2026-08-18T00:16:53.867
Link: CVE-2026-75082
No data.
OpenCVE Enrichment
Updated: 2026-08-18T01:30:05Z