CVE-2026-19995Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message Handler. This manipulation of the argument Message causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-17: 2Technical Details · 2026-08-17: 208-17
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-19995 Cross-Site Scripting in Webkul Bagisto Up To 2.4.4 via RMA Message Handl... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19995 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE-2026-19995, an XSS flaw in Webkul Bagisto up to 2.4.4 via the RMA Message Handler, and links to vulnerability details, but it does not include a PoC, exploit code, or patch information.

    00000104
    4.1K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-19995 A vulnerability was determined in Webkul Bagisto up to 2.4.4. This affects an unknown part of the file /customer/account/rma/send-message of the component RMA Message… https://www.cve.org/CVERecord?id=CVE-2026-19995

    Post summary

    The text notes the identification of CVE-2026-19995 in Webkul Bagisto, mentioning affected files and versions but provides no evidence of exploitation or remediation.

    00000914
    58.0K followersView on X

Explore more