What is CVE-2026-75082?
A stored Cross-Site Scripting (XSS) vulnerability exists in Webkul Bagisto up to version 2.4.4 within the `/customer/register` endpoint, specifically via the `first_name` and `last_name` arguments in the customer registration notification email. This flaw allows a remote attacker to inject and execute malicious scripts in the victim's browser. Users should immediately update to the patched version.
Azərbaycanca: Webkul Bagisto proqramının 2.4.4 versiyasına qədər olan versiyalarında `/customer/register` faylında müştəri qeydiyyatı zamanı `first_name` və `last_name` arqumentlərində saxlanılan XSS (Cross Site Scripting) zəifliyi aşkar edilib. Bu, uzaqdan hücum edənə qurbanın brauzerində zərərli skript icra etməyə imkan verir. Təcili olaraq bu versiyaları ən son yamaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Webkul
FAQ2
Which versions of Webkul Bagisto are affected by the CVE-2026-75082 stored XSS vulnerability?
The vulnerability affects all versions of Webkul Bagisto up to version 2.4.4.
Through which parameters in CVE-2026-75082 can an attacker store a malicious script?
An attacker can inject a malicious script via the `first_name` and `last_name` arguments during customer registration at the `/customer/register` endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.