Skip to content

Known CVE

Bagisto <= 2.4.1 - Unauthenticated Arbitrary File Read

Bagisto through 2.4.1 is vulnerable to unauthenticated path traversal in the ImageCache controller. The `original` image-cache route (/cache/original/{filename}) passes the user-supplied filename to getImagePath() without any '..' filtering or realpath containment, allowing a remote unauthenticated attacker to read files outside the intended public image directories (upload/images) - for example the application's composer.json, artisan and other source files.

CVE-2026-9506

High2026CVSS 8.7CWE-22

cve2026 · bagisto · webkul · lfi · unauth

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website