← back
CVE-2025-60880highCWE-79

CVE-2025-60880

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.3epss 0.4%
exploitation probability
0.4%top 65% of all CVEs
observed exploitation
nono source reports it
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted SVG file containing malicious JavaScript code. This vulnerability can be exploited by an authenticated admin user to execute arbitrary JavaScript in the browser, potentially leading to session hijacking, data theft, or unauthorized actions.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:L/PR:H/S:C/UI:R
Affected products
n/a · n/a