Improper Neutralization of Special Elements Used in a Template Engine in Bagisto - CVE-2026-21448

 

Improper Neutralization of Special Elements Used in a Template Engine in Bagisto - CVE-2026-21448

Published: April 25, 2026


Vulnerability identifier: #VU127910
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21448
CWE-ID: CWE-1336
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to server-side template injection in the checkout address handling and customer address creation functionality when processing user-supplied address input. A remote user can inject a crafted template expression to execute arbitrary code.

Injected input is rendered in the admin order view, and the issue is also reachable through customer address creation.


Affected software

Bagisto

How to mitigate CVE-2026-21448

Install security update from vendor's website.

Bagisto - update to 2.3.10

External References

Related Security Bulletins