HarborGuard / CVE
Back to search
HIGHCVE-2026-21450Published Modified CNA GitHub_M

CVE-2026-21450: Bagisto has SSTI in parameter that can lead to RCE

Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, which can lead to remote code execution or another exploitation. Version 2.3.10 fixes the issue.

Metrics

CVSS v4.0
7.3
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • bagisto / bagisto
    < 2.3.10
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
CVE-2026-21450: Bagisto has SSTI in parameter that can lead to RCE | HarborGuard CVE