CVE-2026-21451

Publication date

2026-01-02 20:37:06

Family

GitHub_M

State

PUBLISHED

Description

Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 within the CMS page editor. Although the platform normally attempts to sanitize `