Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Bagisto - CVE-2026-21451

 

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in Bagisto - CVE-2026-21451

Published: April 25, 2026


Vulnerability identifier: #VU127916
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-21451
CWE-ID: CWE-80
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary script in an administrator's browser.

The vulnerability exists due to improper neutralization of script-related html tags in the CMS page editor when handling a modified CMS update HTTP request. A remote user can submit a specially crafted CMS update request to execute arbitrary script in an administrator's browser.

User interaction is required when an administrator views or edits the affected CMS page.


Affected software

Bagisto

How to mitigate CVE-2026-21451

Install security update from vendor's website.

Bagisto - update to 2.3.10

External References

Related Security Bulletins