Known CVE
Bagisto <= 2.4.1 - Unauthenticated Arbitrary File Read
Bagisto through 2.4.1 is vulnerable to unauthenticated path traversal in the ImageCache controller. The `original` image-cache route (/cache/original/{filename}) passes the user-supplied filename to getImagePath() without any '..' filtering or realpath containment, allowing a remote unauthenticated attacker to read files outside the intended public image directories (upload/images) - for example the application's composer.json, artisan and other source files.
CVE-2026-9506
High2026CVSS 8.7CWE-22
cve2026 · bagisto · webkul · lfi · unauth
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website