What is CVE-2026-19995?
CVE-2026-19995 is a cross-site scripting (XSS) vulnerability found in Webkul Bagisto versions up to 2.4.4, affecting the RMA Message Handler component in the `/customer/account/rma/send-message` file. Remote exploitation is possible via manipulation of the Message argument, and affected systems should be immediately updated to the latest version.
Azərbaycanca: CVE-2026-19995, Webkul Bagisto-nun 2.4.4-ə qədər olan versiyalarında `/customer/account/rma/send-message` faylındakı RMA Message Handler komponentində aşkarlanmış cross-site scripting (XSS) zəifliyidir. Uzaqdan hücum mümkündür, istifadəçilər Message arqumentini manipulyasiya edə bilər. Təsirə məruz qalan sistemlərin dərhal son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Webkul
FAQ2
Which component of Webkul Bagisto is affected by CVE-2026-19995?
CVE-2026-19995 is a cross-site scripting (XSS) vulnerability affecting the RMA Message Handler component in the `/customer/account/rma/send-message` file of Webkul Bagisto versions up to 2.4.4.
What should be done to mitigate CVE-2026-19995?
Affected systems should be immediately updated to the latest version, as the vulnerability allows a remote attacker to manipulate the Message argument.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.