SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-75082

MEDIUM · CVSS 4.3 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the Customer-Registration Notification Email component of Webkul Bagisto versions up to 2.4.4, specifically affecting the handling of the first_name and last_name parameters in the /customer/register file. This flaw allows remote attackers to execute malicious scripts in the context of a user's session, potentially compromising user data and application integrity. Organizations using affected versions should prioritize patching this vulnerability to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-75082
Severity
MEDIUM
CVSS
4.3
EPSS
0.33%

Original NVD Description

A flaw has been found in Webkul Bagisto up to 2.4.4. The affected element is an unknown function of the file /customer/register of the component Customer-Registration Notification Email. This manipulation of the argument first_name/last_name causes basic cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."