PatchSiren

Webkul CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Webkul CVE published 2026-07-09

CVE-2026-60120

CVE-2026-60120 is a stored cross-site scripting vulnerability in Bagisto before version 2.4.4. The vulnerability is caused by client-side template injection that allows unauthenticated attackers to execute arbitrary JavaScript in administrator browsers. This is achieved by registering a customer account with a malicious payload in the first or last name field. The create.blade.php template renders custome [truncated]

HIGH Webkul CVE published 2026-06-19

CVE-2017-20262

CVE-2017-20262 is a high-severity SQL injection vulnerability in Joomla! Component Ajax Quiz 1.8. Unaffected product versions and vendors are unknown. The CVE was published on June 19, 2026. Attackers can inject malicious SQL code through the cid parameter in GET requests to index.php with option=com_ajaxquiz and view=ajaxquiz parameters. This allows extraction of sensitive database information, including [truncated]

HIGH Webkul CVE published 2026-06-08

CVE-2026-9506

CVE-2026-9506 is a high-severity path traversal vulnerability in the ImageCacheController component of Bagisto. This vulnerability, with a CVSS score of 8.7, allows an unauthenticated remote attacker to access arbitrary files outside the intended directory by sending crafted path traversal sequences through the filename parameter. Successful exploitation could enable an attacker to read arbitrary sensitiv [truncated]