Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2024-58341 OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL co… Opencart No fix yet Fix from $1,9502026-03-25 MEDIUM 6.1 CVE-2025-45892 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in t… Opencart after 4.1.0.4 Fix from $1,6002025-07-25 MEDIUM 6.1 CVE-2025-45893 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via SVG file uploads used in blog posts. The vulnerability arise… Opencart after 4.1.0.4 Fix from $1,6002025-07-25 MEDIUM 6.1 CVE-2025-1746 Cross-Site Scripting vulnerability in OpenCart versions prior to 4.1.0. This vulnerability allows an attacker to execute JavaScript code in the victi… Opencart 4.1.0.0+ Fix from $1,6002025-02-28 HIGH 7.2 CVE-2024-36694 OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function. Opencart No fix yet Fix from $1,9502024-12-18 HIGH 7.2 CVE-2024-21518EPSS 14% This affects versions of the package opencart/opencart from 4.0.0.0. A Zip Slip issue was identified via the marketplace installer due to improper sa… Opencart Patch available Fix from $1,9502024-06-22 HIGH 7.2 CVE-2024-21519 This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration fun… Opencart No fix yet Fix from $1,9502024-06-22 MEDIUM 6.1 CVE-2024-21517 This affects versions of the package opencart/opencart from 4.0.0.0. A reflected XSS issue was identified in the redirect parameter of customer accou… Opencart Patch available Fix from $1,6002024-06-22 HIGH 8.1 CVE-2024-21514EPSS 19% This affects versions of the package opencart/opencart from 0.0.0. An SQL Injection issue was identified in the Divido payment extension for OpenCart… Opencart Patch available Fix from $1,9502024-06-22 HIGH 8.8 CVE-2023-47444 An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untr… Opencart after 4.0.2.3 Fix from $1,9502023-11-15 HIGH 8.8 CVE-2023-2315 Path Traversal in OpenCart versions 4.0.0.0 to 4.0.2.2 allows an authenticated user with access/modify privilege on the Log component to empty out ar… Opencart after 4.0.2.2 Fix from $1,9502023-09-27 CRITICAL 9.8 CVE-2023-40834 OpenCart CMS v4.0.2.2 was discovered to lack a protective mechanism on its login page against excessive login attempts, allowing unauthenticated atta… Opencart No fix yet Fix from $2,3002023-09-12 HIGH 7.2 CVE-2020-20491 SQL injection vulnerability in OpenCart v.2.2.00 thru 3.0.3.2 allows a remote attacker to execute arbitrary code via the Fba plugin function in uploa… Opencart after 3.0.3.2 Fix from $1,9502023-06-20 MEDIUM 6.5 CVE-2013-1891EPSS 6% In OpenCart 1.4.7 to 1.5.5.1, implemented anti-traversal code in filemanager.php is ineffective and can be bypassed. Opencart after 1.5.5.1 Fix from $1,6002022-06-24 MEDIUM 5.4 CVE-2020-10596 OpenCart 3.0.3.2 allows remote authenticated users to conduct XSS attacks via a crafted filename in the users' image upload section. Opencart No fix yet Fix from $1,6002020-03-17 HIGH 8.8 CVE-2018-13067 /upload/catalog/controller/account/password.php in OpenCart through 3.0.2.0 has CSRF via the index.php?route=account/password URI to change a user's … Opencart after 3.0.2.0 Fix from $1,9502018-07-02 HIGH 8.0 CVE-2018-11494 The "program extension upload" feature in OpenCart through 3.0.2.0 has a six-step process (upload, install, unzip, move, xml, remove) that allows att… Opencart after 3.0.2.0 Fix from $1,9502018-05-26 CRITICAL 9.8 CVE-2014-3990EPSS 7% The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger… Opencart after 1.5.6.4 Fix from $2,3002018-03-20 HIGH 7.2 CVE-2016-10509 SQL injection vulnerability in the updateAmazonOrderTracking function in upload/admin/model/openbay/amazon.php in OpenCart before version 2.3.0.0 all… Opencart after 2.3.0.0 Fix from $1,9502017-08-31 MEDIUM 6.1 CVE-2015-4671 Cross-site scripting (XSS) vulnerability in OpenCart before 2.1.0.2 allows remote attackers to inject arbitrary web script or HTML via the zone_id pa… Opencart after 2.1.0.1 Fix from $1,6002016-01-12 MEDIUM 5.0 CVE-2011-3763 OpenCart 1.4.9.3 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in … Opencart No fix yet Fix from $1,6002011-09-24 MEDIUM 6.8 CVE-2010-1610 Cross-site request forgery (CSRF) vulnerability in index.php in OpenCart 1.4 allows remote attackers to hijack the authentication of an application a… Opencart Mitigation only Fix from $1,6002010-04-29 HIGH 7.5 CVE-2010-0956 SQL injection vulnerability in index.php in OpenCart 1.3.2 allows remote attackers to execute arbitrary SQL commands via the page parameter. Opencart No fix yet Fix from $1,9502010-03-10 MEDIUM 5.0 CVE-2009-1621EPSS 6% Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the route para… Opencart No fix yet Fix from $1,6002009-05-12 HIGH 7.5 CVE-2009-1027 SQL injection vulnerability in OpenCart 1.1.8 allows remote attackers to execute arbitrary SQL commands via the order parameter. Opencart Mitigation only Fix from $1,9502009-03-20