Vulnerability index

Browse CVEs

10 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2024-58341 OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co… Opencart No fix yet Fix from $1,9502026-03-25 HIGH 7.2 CVE-2024-36694 OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function. Opencart No fix yet Fix from $1,9502024-12-18 HIGH 7.2 CVE-2024-21519 This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration fun… Opencart No fix yet Fix from $1,9502024-06-22 CRITICAL 9.8 CVE-2023-40834 OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated atta… Opencart No fix yet Fix from $2,3002023-09-12 MEDIUM 5.4 CVE-2020-10596 OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section. Opencart No fix yet Fix from $1,6002020-03-17 MEDIUM 5.0 CVE-2011-3763 OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … Opencart No fix yet Fix from $1,6002011-09-24 MEDIUM 6.8 CVE-2010-1610 Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application a… Opencart Mitigation only Fix from $1,6002010-04-29 HIGH 7.5 CVE-2010-0956 SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter. Opencart No fix yet Fix from $1,9502010-03-10 MEDIUM 5.0 CVE-2009-1621EPSS 6% Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route para… Opencart No fix yet Fix from $1,6002009-05-12 HIGH 7.5 CVE-2009-1027 SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter. Opencart Mitigation only Fix from $1,9502009-03-20