# CVE-2025-62418

## Summary

- **CVE ID:** CVE-2025-62418
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N)
- **CWE:** CWE-80, CWE-87
- **Published:** Oct 16, 2025
- **Last Modified:** Mar 13, 2026

## Description

Bagisto is an open source laravel eCommerce platform. In Bagisto v2.3.7, the TinyMCE image upload functionality allows an attacker with sufficient privileges (e.g. admin) to upload a crafted SVG file containing embedded JavaScript. When viewed, the malicious code executes in the context of the admin/user’s browser. This vulnerability is fixed in 2.3.8.

## Affected Products

- bagisto — bagisto (< 2.3.8)

## References

- [CNA](https://github.com/bagisto/bagisto/security/advisories/GHSA-fg89-g389-p346)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._