Improper Neutralization of Special Elements Used in a Template Engine in Bagisto - CVE-2026-21448
Published: April 25, 2026
Bagisto
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to server-side template injection in the checkout address handling and customer address creation functionality when processing user-supplied address input. A remote user can inject a crafted template expression to execute arbitrary code.
Injected input is rendered in the admin order view, and the issue is also reachable through customer address creation.