Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.2
CVE-2024-58341
OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co…
Opencart
No fix yet
MEDIUM 6.1
CVE-2025-45892
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in t…
Opencart
after 4.1.0.4
MEDIUM 6.1
CVE-2025-45893
OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arise…
Opencart
after 4.1.0.4
MEDIUM 6.1
CVE-2025-1746
Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victi…
Opencart
4.1.0.0+
HIGH 7.2
CVE-2024-36694
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
Opencart
No fix yet
HIGH 7.2
CVE-2024-21518EPSS 14%
This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sa…
Opencart
Patch available
HIGH 7.2
CVE-2024-21519
This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration fun…
Opencart
No fix yet
MEDIUM 6.1
CVE-2024-21517
This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer accou…
Opencart
Patch available
HIGH 8.1
CVE-2024-21514EPSS 19%
This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart…
Opencart
Patch available
HIGH 8.8
CVE-2023-47444
An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untr…
Opencart
after 4.0.2.3
HIGH 8.8
CVE-2023-2315
Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out ar…
Opencart
after 4.0.2.2
CRITICAL 9.8
CVE-2023-40834
OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated atta…
Opencart
No fix yet
HIGH 7.2
CVE-2020-20491
SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in uploa…
Opencart
after 3.0.3.2
MEDIUM 6.5
CVE-2013-1891EPSS 6%
In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed.
Opencart
after 1.5.5.1
MEDIUM 5.4
CVE-2020-10596
OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section.
Opencart
No fix yet
HIGH 8.8
CVE-2018-13067
/upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's …
Opencart
after 3.0.2.0
HIGH 8.0
CVE-2018-11494
The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows att…
Opencart
after 3.0.2.0
CRITICAL 9.8
CVE-2014-3990EPSS 7%
The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger…
Opencart
after 1.5.6.4
HIGH 7.2
CVE-2016-10509
SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 all…
Opencart
after 2.3.0.0
MEDIUM 6.1
CVE-2015-4671
Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id pa…
Opencart
after 2.1.0.1
MEDIUM 5.0
CVE-2011-3763
OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in …
Opencart
No fix yet
MEDIUM 6.8
CVE-2010-1610
Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application a…
Opencart
Mitigation only
HIGH 7.5
CVE-2010-0956
SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter.
Opencart
No fix yet
MEDIUM 5.0
CVE-2009-1621EPSS 6%
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route para…
Opencart
No fix yet
HIGH 7.5
CVE-2009-1027
SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter.
Opencart
Mitigation only