Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Opencart HIGH 8.2
CVE-2024-58341

OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co…

No fix yet
Fix from $1,950 2026-03-25
Opencart HIGH 7.2
CVE-2024-36694

OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.

No fix yet
Fix from $1,950 2024-12-18
Opencart HIGH 7.2
CVE-2024-21519

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration fun…

No fix yet
Fix from $1,950 2024-06-22
Opencart CRITICAL 9.8
CVE-2023-40834

OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated atta…

No fix yet
Fix from $2,300 2023-09-12
Opencart MEDIUM 5.4
CVE-2020-10596

OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.

No fix yet
Fix from $1,600 2020-03-17
Opencart MEDIUM 5.0
CVE-2011-3763

OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …

No fix yet
Fix from $1,600 2011-09-24
Opencart MEDIUM 6.8
CVE-2010-1610

Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application a…

Mitigation only
Fix from $1,600 2010-04-29
Opencart HIGH 7.5
CVE-2010-0956

SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.

No fix yet
Fix from $1,950 2010-03-10
Opencart MEDIUM 5.0
CVE-2009-1621EPSS 6%

Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route para…

No fix yet
Fix from $1,600 2009-05-12
Opencart HIGH 7.5
CVE-2009-1027

SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.

Mitigation only
Fix from $1,950 2009-03-20