Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Opencart HIGH 8.2
CVE-2024-58341

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co…

No fix yet
Fix from $1,950 2026-03-25
Opencart MEDIUM 6.1
CVE-2025-45892

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in t…

Fix: after 4.1.0.4
Fix from $1,600 2025-07-25
Opencart MEDIUM 6.1
CVE-2025-45893

OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arise…

Fix: after 4.1.0.4
Fix from $1,600 2025-07-25
Opencart MEDIUM 6.1
CVE-2025-1746

Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victi…

Fix: 4.1.0.0+
Fix from $1,600 2025-02-28
Opencart HIGH 7.2
CVE-2024-36694

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

No fix yet
Fix from $1,950 2024-12-18
Opencart HIGH 7.2
CVE-2024-21518EPSS 14%

This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sa…

Patch available
Fix from $1,950 2024-06-22
Opencart HIGH 7.2
CVE-2024-21519

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration fun…

No fix yet
Fix from $1,950 2024-06-22
Opencart MEDIUM 6.1
CVE-2024-21517

This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer accou…

Patch available
Fix from $1,600 2024-06-22
Opencart HIGH 8.1
CVE-2024-21514EPSS 19%

This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart…

Patch available
Fix from $1,950 2024-06-22
Opencart HIGH 8.8
CVE-2023-47444

An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untr…

Fix: after 4.0.2.3
Fix from $1,950 2023-11-15
Opencart HIGH 8.8
CVE-2023-2315

Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out ar…

Fix: after 4.0.2.2
Fix from $1,950 2023-09-27
Opencart CRITICAL 9.8
CVE-2023-40834

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated atta…

No fix yet
Fix from $2,300 2023-09-12
Opencart HIGH 7.2
CVE-2020-20491

SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in uploa…

Fix: after 3.0.3.2
Fix from $1,950 2023-06-20
Opencart MEDIUM 6.5
CVE-2013-1891EPSS 6%

In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.

Fix: after 1.5.5.1
Fix from $1,600 2022-06-24
Opencart MEDIUM 5.4
CVE-2020-10596

OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.

No fix yet
Fix from $1,600 2020-03-17
Opencart HIGH 8.8
CVE-2018-13067

/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's …

Fix: after 3.0.2.0
Fix from $1,950 2018-07-02
Opencart HIGH 8.0
CVE-2018-11494

The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows att…

Fix: after 3.0.2.0
Fix from $1,950 2018-05-26
Opencart CRITICAL 9.8
CVE-2014-3990EPSS 7%

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger…

Fix: after 1.5.6.4
Fix from $2,300 2018-03-20
Opencart HIGH 7.2
CVE-2016-10509

SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 all…

Fix: after 2.3.0.0
Fix from $1,950 2017-08-31
Opencart MEDIUM 6.1
CVE-2015-4671

Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id pa…

Fix: after 2.1.0.1
Fix from $1,600 2016-01-12
Opencart MEDIUM 5.0
CVE-2011-3763

OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

No fix yet
Fix from $1,600 2011-09-24
Opencart MEDIUM 6.8
CVE-2010-1610

Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application a…

Mitigation only
Fix from $1,600 2010-04-29
Opencart HIGH 7.5
CVE-2010-0956

SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

No fix yet
Fix from $1,950 2010-03-10
Opencart MEDIUM 5.0
CVE-2009-1621EPSS 6%

Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route para…

No fix yet
Fix from $1,600 2009-05-12
Opencart HIGH 7.5
CVE-2009-1027

SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

Mitigation only
Fix from $1,950 2009-03-20