Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-56426


An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calculation logic fails to validate quantity inputs properly.


Published

2025-10-09T16:15:45.480

Last Modified

2025-10-30T14:30:40.043

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application webkul bagisto 2.3.6 Yes

References