CVE-2026-79409
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 15, 2026
Vendor
unknown
Description
An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.