PT-2026-34047 · Bagisto · Bagisto

Hai271120

·

Published

2026-04-21

·

Updated

2026-04-22

·

CVE-2026-6745

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bagisto versions prior to 2.3.16
Description An issue exists in the Custom Scripts Handler component that allows for cross site scripting. This flaw enables remote exploitation through the manipulation of an unknown functionality within the component.
Recommendations Update to a version newer than 2.3.15.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-6745
GHSA-65FP-7G2V-658R

Affected Products

Bagisto