Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-62416

Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descriptions. This allows an attacker with product creation privileges to inject arbitrary template expressions that are evaluated by the backend — potentially leading to Remote Code Execution (RCE) on the server. This vulnerability is fixed in 2.3.8.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 32.1%
CVSS Severity
CVSS v3 Score 5.1
Products affected by CVE-2025-62416
  • Webkul » Bagisto » Version: 2.3.7
    cpe:2.3:a:webkul:bagisto:2.3.7


Contact Us

Shodan ® - All rights reserved