PT-2026-34047 · Bagisto · Bagisto

·

CVE-2026-6745

·

Published

2026-04-21

·

Updated

2026-04-22

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Bagisto versions prior to 2.3.16
Description An issue exists in the Custom Scripts Handler component that allows for cross site scripting. This flaw enables remote exploitation through the manipulation of an unknown functionality within the component.
Recommendations Update to a version newer than 2.3.15.

Exploit

Fix

Code Injection

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6745
GHSA-65FP-7G2V-658R

Affected Products

Bagisto