CVE-2025-62416: Webkul Bagisto

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with product creation privileges to inject arbitrary template expressions that are evaluated by the backend — potentially leading to Remote Code Execution (RCE) on the server. This vulnerability is fixed in 2.3.8.

Affected products

  • Webkul Bagisto: version 2.3.7 only

Published 2025-10-16. Last modified 2026-06-17.